QID 981095
QID 981095: Nodejs (npm) Security Update for uap-core (GHSA-fx7m-j728-mjw3)
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string. (The UAP-Core project contains the vulnerability, propagating to all implementations.)
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fx7m-j728-mjw3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fx7m-j728-mjw3 -
github.com/advisories/GHSA-fx7m-j728-mjw3
CVEs related to QID 981095
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fx7m-j728-mjw3 | uap-core |
|