Vulnerability library
Security checkJune 15, 2026

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmua-parser-js

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A regular expression denial-of-service (ReDoS) vulnerability has been discovered in ua-parser-js when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause the parser to spend excessive CPU time due to catastrophic backtracking in the device regex:

Unlike when using the User-Agent value, which has a hard limit of UA_MAX_LENGTH = 500, when using Client Hints, values are copied without a length limit before being passed into regex parsing.

Recommendation

Update the ua-parser-js package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 2.0.1, < 2.0.10
  • Patched version(s): 2.0.10

References

Could your website be exposed too?

SmartScanner can check your website for UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()` and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 15, 2026