All the vulnerabilities related to the version 1.2.1 of the package
Regular Expression Denial of Service in sshpk
Versions of sshpk
before 1.13.2 or 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.
Update to version 1.13.2, 1.14.1 or later.