Junglewise Threat Intelligence

CVE-2017-16030: useragent ReDoS via long User-Agent header

CVE-2017-16030 · Severity: info · CVSS 7.5 · Published 2018-07-24

Vendors: npm.

Executive brief

The useragent library parses HTTP User-Agent headers to identify browsers and devices. A vulnerability in its regular expression engine allows an attacker to send a specially crafted User-Agent header with a very long string, causing the parsing operation to consume excessive CPU and hang indefinitely. This can cause denial of service to any web application that uses this library to parse user requests.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) issue in the User-Agent parsing logic, classified as CWE-400 (Uncontrolled Resource Consumption). When a maliciously crafted User-Agent header with an arbitrarily long string is passed to the parser, the regular expression engine enters catastrophic backtracking, consuming CPU resources and freezing the application. The attack requires only a network-reachable service with no authentication; the attacker simply sends an HTTP request with the malicious User-Agent header. The impact is a complete denial of service to the affected application. The vulnerability was patched in version 2.1.13 and all versions prior to 2.1.12 are affected.

Affected products

  • useragent useragent <= 2.1.12

Timeline

  • 2018-07-24: disclosed
  • 2018-07-24: patched: Version 2.1.13 released with fix

Related threats