Description
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string.
Recommendation
Update the uap-core package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.0
- Patched version(s): 0.6.0
References
Related Issues
- Regular Expression Denial of Service in ssri - CVE-2018-7651
- Denial of Service in uap-core - CVE-2021-21317
- Denial of Service in uap-core when processing crafted User-Agent strings - CVE-2020-5243
- Regular Expression Denial of Service in highcharts (GHSA-xmc8-cjfr-phx3) - CVE-2018-20801
- Tags:
- npm
- uap-core
Anything's wrong? Let us know Last updated on January 23, 2023