Description
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
Remediation
References
https://github.com/kevva/url-regex/issues/70
https://snyk.io/vuln/SNYK-JS-URLREGEX-569472
Related Vulnerabilities
CVE-2021-23374 Vulnerability in npm package ps-visitor
CVE-2022-25883 Vulnerability in npm package semver
CVE-2020-10758 Vulnerability in maven package org.keycloak:keycloak-wildfly-server-subsystem
CVE-2022-36083 Vulnerability in npm package jose-node-cjs-runtime
CVE-2021-28164 Vulnerability in maven package org.eclipse.jetty:jetty-webapp