Lucene search

K
nodejsAnonymousNODEJS:1679
HistoryMay 06, 2021 - 4:15 p.m.

Regular Expression Denial of Service

2021-05-0616:15:15
Anonymous
www.npmjs.com
29

0.002 Low

EPSS

Percentile

64.6%

Overview

ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.

Recommendation

Upgrade to version 0.7.24 or later

References

CPENameOperatorVersion
ua-parser-jsge0.7.14 <0.7.24