Description
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Remediation
References
https://nodesecurity.io/advisories/533
https://github.com/indexzero/TimeSpan.js/issues/10
Related Vulnerabilities
CVE-2019-1003000 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-21320 Vulnerability in npm package matrix-react-sdk
CVE-2021-32854 Vulnerability in npm package textangular
CVE-2020-28472 Vulnerability in npm package @aws-sdk/shared-ini-file-loader
CVE-2022-24898 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml