Description
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
Remediation
References
https://nodesecurity.io/advisories/312
Related Vulnerabilities
CVE-2017-16109 Vulnerability in npm package easyquick
CVE-2016-8749 Vulnerability in maven package org.apache.camel:camel-jackson
CVE-2021-43138 Vulnerability in maven package org.webjars:async
CVE-2022-45210 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2021-43309 Vulnerability in npm package uri-template-lite