VDB
Sign up
HIGH7.5

GHSA-p4pj-mg4r-x6v4

Denial of Service in uap-core

Quick fix

GHSA-p4pj-mg4r-x6v4 — uap-core: upgrade to the fixed version with the command below.

npm install uap-core@0.11.0

Details

## Impact

Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.

## Patches

Please update uap-core to >= v0.11.0

Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/uap-core
Introduced in: 0Fixed in: 0.11.0
Fixnpm install uap-core@0.11.0

References