Description
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Remediation
References
https://hackerone.com/reports/319593
Related Vulnerabilities
CVE-2021-23566 Vulnerability in npm package nanoid
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri
CVE-2022-24728 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2022-31160 Vulnerability in maven package org.webjars:jquery-ui
CVE-2016-0712 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed-portal