uap-core Regular Expression Denial of Service issue
Moderate severity
GitHub Reviewed
Published
Mar 6, 2019
to the GitHub Advisory Database
•
Updated Jan 23, 2023
Description
Published to the GitHub Advisory Database
Mar 6, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 23, 2023
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string. (The UAP-Core project contains the vulnerability, propagating to all implementations.)
References