### [CVE-2021-23490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23490) ![](https://img.shields.io/static/v1?label=Product&message=parse-link-header&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Regular%20Expression%20Denial%20of%20Service%20(ReDoS)&color=brightgreen) ### Description The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function. ### POC #### Reference - https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2321973 - https://snyk.io/vuln/SNYK-JS-PARSELINKHEADER-1582783 #### Github - https://github.com/engn33r/awesome-redos-security