### [CVE-2021-23392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23392) ![](https://img.shields.io/static/v1?label=Product&message=locutus&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Regular%20Expression%20Denial%20of%20Service%20(ReDoS)&color=brightgreen) ### Description The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function. ### POC #### Reference - https://snyk.io/vuln/SNYK-JS-LOCUTUS-1090597 #### Github No PoCs found on GitHub currently.