Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2021-27884 Vulnerability in npm package yapi-vendor
CVE-2018-18893 Vulnerability in maven package com.hubspot.jinjava:jinjava
CVE-2021-3647 Vulnerability in npm package urijs
CVE-2021-23416 Vulnerability in npm package curly-bracket-parser