The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
Statement: Red Hat Quay imports nodejs-no-case as a build time dependency of html-loader. Nodejs-no-case is only used as build time, and not at runtime.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-16099