Description
All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.
Remediation
References
https://github.com/dataarts/dat.gui/issues/278
https://snyk.io/vuln/SNYK-JS-DATGUI-1016275
Related Vulnerabilities
CVE-2022-37616 Vulnerability in npm package xmldom
CVE-2021-23327 Vulnerability in npm package apexcharts
CVE-2022-35924 Vulnerability in npm package next-auth
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2023-48711 Vulnerability in maven package org.webjars.npm:google-translate-api-browser