VDB
Sign up
MEDIUM5.3

GHSA-fx7m-j728-mjw3

uap-core Regular Expression Denial of Service issue

Quick fix

GHSA-fx7m-j728-mjw3 — uap-core: upgrade to the fixed version with the command below.

npm install uap-core@0.6.0

Details

An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string. (The UAP-Core project contains the vulnerability, propagating to all implementations.)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/uap-core
Introduced in: 0Fixed in: 0.6.0
Fixnpm install uap-core@0.6.0

References