Description
Affected versions of ua-parser are vulnerable to regular expression denial of service when given a specially crafted User-Agent header.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.3.5
References
Could your website be exposed too?
SmartScanner can check your website for ReDoS via long UserAgent header in ua-parser and gives you actionable findings to investigate.
Start a free scanRelated Issues
- ReDoS via long UserAgent header in useragent - CVE-2017-16030
- SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header - CVE-2026-66062
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


