It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
{ "nvd_published_at": "2021-01-26T21:15:00Z", "github_reviewed_at": "2021-10-07T19:01:30Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-829" ] }