Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2020-7713 Vulnerability in npm package arr-flatten-unflatten
CVE-2022-36067 Vulnerability in npm package vm2
CVE-2020-26299 Vulnerability in npm package ftp-srv
CVE-2016-5007 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2016-10604 Vulnerability in npm package dalek-browser-chrome