Executive brief
ua-parser is a JavaScript library used to parse and analyze User-Agent headers from web browsers and HTTP clients. A specially crafted User-Agent header can trigger a regular expression denial of service (ReDoS) attack, causing the application to consume excessive CPU and become unresponsive. No patch has been released; the recommended mitigation is to replace ua-parser with an alternative library such as useragent.
Technical details
This vulnerability is a regular expression denial of service (ReDoS) triggered by a specially crafted User-Agent header that causes catastrophic backtracking in the library's parsing regex. The vulnerable component is the User-Agent parsing routine in ua-parser up to version 0.3.5. The attack vector is network-based and requires no authentication; an attacker can send a malicious HTTP request with a crafted User-Agent header to trigger the vulnerability. This results in denial of service through CPU exhaustion. No patch has been released for this vulnerability, and the advisory recommends migrating to an alternative user-agent parsing library.
Affected products
- ua-parser contributors ua-parser 0.3.5 and earlier
Timeline
- 2018-07-24: disclosed