Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29751
HistoryMar 18, 2021 - 4:30 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-03-1804:30:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.002 Low

EPSS

Percentile

64.6%

ua-parser-js is vulnerable to regular expression denial of service. An attacker is able to exploit the vulnerability by sending a malicious User-Agent header under the device type causing the system to process the header for an extended period of time.