0.002 Low
EPSS
Percentile
54.1%
Versions of sshpk before 1.13.2 or 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.
sshpk
Update to version 1.13.2, 1.14.1 or later.
github.com/advisories/GHSA-2m39-62fm-q8r3
github.com/joyent/node-sshpk/blob/v1.13.1/lib/formats/ssh.js#L17
github.com/joyent/node-sshpk/commit/46065d38a5e6d1bccf86d3efb2fb83c14e3f9957
hackerone.com/reports/319593
nvd.nist.gov/vuln/detail/CVE-2018-3737
www.npmjs.com/advisories/606