Description
The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.
Remediation
References
https://github.com/locutusjs/locutus/commit/eb863321990e7e5514aa14f68b8d9978ece9e65e
https://github.com/locutusjs/locutus/pull/446
https://snyk.io/vuln/SNYK-JS-LOCUTUS-1090597
Related Vulnerabilities
CVE-2021-3377 Vulnerability in npm package ansi_up
CVE-2020-35451 Vulnerability in maven package org.apache.oozie:oozie-tools
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:openejb-core
CVE-2020-14060 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-client