The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Leftama/safenotes