#VU55667 Resource exhaustion in UAParser.js - CVE-2021-27292
Published: August 9, 2021
UAParser.js
Faisal Salman
Description
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing a malicious User-Agent header. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.