Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2021-23900 Vulnerability in maven package com.mikesamuel:json-sanitizer
CVE-2017-16168 Vulnerability in npm package wffserve
CVE-2022-41853 Vulnerability in maven package org.hsqldb:hsqldb
CVE-2017-16107 Vulnerability in npm package pooledwebsocket
CVE-2018-19838 Vulnerability in maven package org.webjars.npm:node-sass