The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD"
},
{
"source": "CPE_FIELD",
"vendor_product": "trim-newlines_project:trim-newlines",
"extracted_events": [
{
"fixed": "3.0.1"
}
],
"cpes": [
"cpe:2.3:a:trim-newlines_project:trim-newlines:*:*:*:*:*:node.js:*:*"
]
}
]
}