A flaw was found in sshpk versions before 1.14.1. The regular expressions used for parsing OpenSSH-format public keys in sshpk are resulting in exponential increases in runtime when parsing maliciously constructed inputs.
References: https://github.com/joyent/node-sshpk/issues/44
Pacth: https://github.com/joyent/node-sshpk/commit/46065d38a5e6d1bccf86d3efb2fb83c14e3f9957