All the vulnerabilities related to the version 4.1.6 of the package
Regular Expression Denial of Service in ssri
Version of ssri
prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.
Update to version 5.2.2 or later.