The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
{ "binaries": [ { "binary_name": "node-got", "binary_version": "11.8.3+~cs58.7.37-1" } ] }
{ "binaries": [ { "binary_name": "yarnpkg", "binary_version": "1.22.10+~cs22.25.14-8" } ] }
{ "binaries": [ { "binary_name": "node-got", "binary_version": "11.8.5+~cs58.13.36-3" } ] }
{ "binaries": [ { "binary_name": "yarnpkg", "binary_version": "1.22.19+~cs24.27.18-4" } ] }
{ "binaries": [ { "binary_name": "node-got", "binary_version": "11.8.5+~cs58.13.36-5" } ] }
{ "binaries": [ { "binary_name": "yarnpkg", "binary_version": "4.0.2+dfsg-3" } ] }
{ "binaries": [ { "binary_name": "yarnpkg", "binary_version": "4.1.0+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "node-got", "binary_version": "7.1.0-1" } ] }
{ "binaries": [ { "binary_name": "yarnpkg", "binary_version": "1.22.4-2" } ] }