GHSA-2m39-62fm-q8r3
GitHub Security Advisory
Regular Expression Denial of Service in sshpk
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of `sshpk` before 1.13.2 or 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.
## Recommendation
Update to version 1.13.2, 1.14.1 or later.
Affected Packages
npm
sshpk
Affected versions:
0
(fixed in 1.13.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 4, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.