Vulnerabilities/

uap-core Regular Expression Denial of Service issue

Severity:
Medium

Description

An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string.

Recommendation

Update the uap-core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
uap-core
Anything's wrong? Let us know Last updated on January 23, 2023

This issue is available in SmartScanner Professional

See Pricing