Description
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
Remediation
References
https://github.com/blakeembrey/no-case/issues/17
https://nodesecurity.io/advisories/529
Related Vulnerabilities
CVE-2018-19057 Vulnerability in maven package org.webjars.npm:simplemde
CVE-2020-5219 Vulnerability in maven package org.webjars.npm:angular-expressions
CVE-2021-43308 Vulnerability in npm package markdown-link-extractor
CVE-2016-10544 Vulnerability in npm package uws
CVE-2017-17485 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind