VDB
Sign up
HIGH

GHSA-pcqq-5962-hvcw

Denial of Service in uap-core when processing crafted User-Agent strings

Quick fix

GHSA-pcqq-5962-hvcw — user_agent_parser: upgrade to the fixed version with the command below.

bundle update user_agent_parser

Details

### Impact Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.

### Patches Please update `uap-ruby` to >= v2.6.0

### For more information https://github.com/ua-parser/uap-core/security/advisories/GHSA-cmcx-xhr8-3w9p

Reported in `uap-core` by Ben Caller @bcaller

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/user_agent_parser
Introduced in: 0Fixed in: 2.6.0
Fixbundle update user_agent_parser

References