Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Remediation
References
https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/
Related Vulnerabilities
CVE-2021-32820 Vulnerability in npm package express-handlebars
CVE-2022-33987 Vulnerability in maven package org.webjars.npm:got
CVE-2020-28472 Vulnerability in npm package @aws-sdk/shared-ini-file-loader
CVE-2010-1244 Vulnerability in maven package org.apache.activemq:activemq-web
CVE-2021-39168 Vulnerability in npm package @openzeppelin/contracts-upgradeable