Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Remediation
References
https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/
Related Vulnerabilities
CVE-2021-3795 Vulnerability in npm package semver-regex
CVE-2021-21423 Vulnerability in npm package projen
CVE-2017-16143 Vulnerability in npm package commentapp.stetsonwood
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-default