Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Remediation
References
https://research.jfrog.com/vulnerabilities/semver-regex-redos-xray-211349/
Related Vulnerabilities
CVE-2021-32851 Vulnerability in npm package mind-elixir
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-client
CVE-2022-25847 Vulnerability in npm package serve-lite
CVE-2019-16762 Vulnerability in npm package slpjs
CVE-2022-25873 Vulnerability in maven package org.webjars.npm:vuetify