Related Vulnerabilities: CVE-2021-27290  

A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the ssri npm module which may be vulnerable to denial of service attacks.

Severity High

Remote Yes

Type Denial of service

Description

A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the ssri npm module which may be vulnerable to denial of service attacks.

AVG-2129 nodejs-lts-dubnium 10.24.0-2 High Vulnerable

AVG-2128 nodejs-lts-erbium 12.22.0-2 High Vulnerable

AVG-2127 nodejs-lts-fermium 14.16.0-2 High Vulnerable

AVG-2126 nodejs 16.4.0-1 16.4.1-1 High Fixed

https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/#npm-upgrade-ssri-regular-expression-denial-of-service-redos-high-cve-2021-27290
https://github.com/advisories/GHSA-vx3p-948g-6vhq
https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf
https://github.com/npm/ssri/pull/17
https://github.com/npm/ssri/commit/76e223317d971f19e4db8191865bdad5edee40d2