CVE-2021-27292 PUBLISHED

ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.

EPSS 0.27% · 50.0th percentile

Risk Scores

EPSS Score
0.27%
50.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-ua-parser-js0.7.14-1, 0
Ubuntu:22.04:LTSnode-ua-parser-js0.7.24+ds-1, 0.7.31+ds+~0.7.36-1, 0.7.24+ds-2
Ubuntu:20.04:LTSnode-ua-parser-js0, 0.7.14-1

Timeline

References

Open in Interactive Console →