Description
Affected versions of useragent are vulnerable to regular expression denial of service when an arbitrarily long User-Agent header is parsed.
Recommendation
Update the useragent package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.1.12
- Patched version(s): 2.1.13
References
Related Issues
- ReDoS via long UserAgent header in ua-parser - CVE-2017-16086
- SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header - CVE-2026-66062
- LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection - CVE-2026-25528
- Content Injection via TileJSON Name in mapbox.js - CVE-2017-1000043
You might also like:
- Tags:
- npm
- useragent
Anything's wrong? Let us know Last updated on September 06, 2023


