Description
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Remediation
References
https://github.com/indexzero/TimeSpan.js/issues/10
https://nodesecurity.io/advisories/533
Related Vulnerabilities
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2023-27602 Vulnerability in maven package org.apache.linkis:linkis-storage-script-dev-server
CVE-2021-29943 Vulnerability in maven package org.apache.solr:solr-core
CVE-2023-34616 Vulnerability in maven package com.progsbase.libraries:json