Affected versions of tough-cookie may be vulnerable to regular expression denial of service when long strings of semicolons exist in the Set-Cookie header.
tough-cookie
Set-Cookie
Update to version 2.3.0 or later.