Description
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
Remediation
References
https://nodesecurity.io/advisories/312
Related Vulnerabilities
CVE-2021-32822 Vulnerability in npm package hbs
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net
CVE-2021-23446 Vulnerability in npm package handsontable
CVE-2019-15596 Vulnerability in npm package statics-server
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs