All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) [DNP] via trim().