The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
{ "binaries": [ { "binary_version": "7.1.0-1", "binary_name": "node-got" } ] }
{ "binaries": [ { "binary_version": "1.22.4-2", "binary_name": "yarnpkg" } ] }
{ "binaries": [ { "binary_version": "11.8.3+~cs58.7.37-1", "binary_name": "node-got" } ] }
{ "binaries": [ { "binary_version": "1.22.10+~cs22.25.14-8", "binary_name": "yarnpkg" } ] }
{ "binaries": [ { "binary_version": "11.8.5+~cs58.13.36-3", "binary_name": "node-got" } ] }
{ "binaries": [ { "binary_version": "1.22.19+~cs24.27.18-4", "binary_name": "yarnpkg" } ] }
{ "binaries": [ { "binary_version": "11.8.5+~cs58.13.36-5", "binary_name": "node-got" } ] }
{ "binaries": [ { "binary_version": "4.0.2+dfsg-3", "binary_name": "yarnpkg" } ] }