Description
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2683 Vulnerability (CVE-2019-2683)
SharePoint Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-58639)
WordPress Plugin Post Pay Counter PHP Object Injection (2.730)
WordPress Plugin WPFront Scroll Top Cross-Site Scripting (2.0.5.07184)
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2020-27223)