It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
{
"github_reviewed": true,
"nvd_published_at": "2021-01-26T21:15:00Z",
"github_reviewed_at": "2021-10-07T19:01:30Z",
"cwe_ids": [
"CWE-829"
],
"severity": "MODERATE"
}