Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package conistring
CVE-2019-11003 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2023-46652 Vulnerability in maven package org.jenkins-ci.plugins:lambdatest-automation
CVE-2020-1935 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2020-7661 Vulnerability in maven package org.webjars.npm:url-regex