CVE-2022-25881
Simple Local Avatars versions prior to 2.7.4 contain a Regular Expression Denial of Service vulnerability through the http-cache-semantics package affecting how cache-control HTTP headers are processed. This vulnerability could potentially allow attackers to cause a denial of service condition by crafting malicious cache-control headers. The flaw was resolved in version 2.7.4 and later. While the underlying package contains this ReDoS issue, actual exploitability depends on the specific implementation within the plugin.
Based on public CVE data (MITRE/NVD).