Description
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Remediation
References
https://hackerone.com/reports/319593
Related Vulnerabilities
CVE-2017-16189 Vulnerability in npm package sly07
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js
CVE-2023-1454 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked