The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function. See:
https://github.com/IBM/tpf-conceptnet-datasource/security/dependabot/1
The dependency chain is as follows: parse-link-header 1.0.1
> @comunica/actor-http-native 1.22.1
> rdf-parse 1.9.1
> componentsjs 4.5.0 > @ldf/core 3.2.1
(the one used here). The >
represents the required by relation.