Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Remediation
References
https://research.jfrog.com/vulnerabilities/semver-regex-redos-xray-211349/
Related Vulnerabilities
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl
CVE-2017-16141 Vulnerability in npm package lab6drewfusbyu
CVE-2021-26544 Vulnerability in maven package org.apache.livy:livy-server
CVE-2023-27096 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents.client5:httpclient5