Resource exhaustion in UAParser.js - #VU27691
Published: May 11, 2020
UAParser.js
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing data with regular expressions. A remote attacker can pass specially crafted data to the application and perform a regular expression denial of service attack (ReDoS).