Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Remediation
References
https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/
Related Vulnerabilities
CVE-2015-0250 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2020-36381 Vulnerability in npm package aaptjs
CVE-2019-10789 Vulnerability in npm package curling
CVE-2017-16198 Vulnerability in npm package ritp
CVE-2018-1002202 Vulnerability in maven package net.lingala.zip4j:zip4j