Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2021-23344 Vulnerability in npm package total.js
CVE-2020-7691 Vulnerability in maven package org.webjars.bower:jspdf
CVE-2016-6346 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone-components