Vulnerabilities/

Regular Expression Denial of Service in sshpk

Severity:
High

Description

Versions of sshpk before 1.13.2 or 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.

Recommendation

Update the sshpk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sshpk
Anything's wrong? Let us know Last updated on January 31, 2023

This issue is available in SmartScanner Professional

See Pricing