CVE-2018-3737: Incorrect Regular Expression
(updated )
sshpk is vulnerable to ReDoS when parsing maliciously crafted invalid public keys.
References
Detect and mitigate CVE-2018-3737 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →