Junglewise Threat Intelligence

CVE-2018-20164: UA-Parser uap-core regular expression denial of service

CVE-2018-20164 · Severity: low · CVSS 3 · Published 2019-03-06

Technologies: uap-core (npm). Vendors: npm.

Executive brief

UA-Parser is a widely-used library that identifies browser and device types from HTTP User-Agent headers. A flaw in its regular expression patterns allows attackers to craft malicious User-Agent strings with long digit sequences, causing the parsing logic to hang and consume CPU resources. This can be exploited remotely to degrade or disable services that depend on uap-core for user agent detection.

Technical details

This is a Regular Expression Denial of Service (ReDoS) vulnerability in the regex.yaml pattern definitions used by UA-Parser uap-core. The vulnerable regex patterns (such as `^(.*)/(\d+)\.?(\d+)?\.?(\d+)?\.?(\d+)? CFNetwork`) employ optional quantifiers and alternation that cause catastrophic backtracking when matched against a long string of digits. An attacker can trigger excessive CPU consumption by setting the User-Agent HTTP header to a value containing repeated digits, causing the regex engine to hang during parsing. The vulnerability affects all versions prior to 0.6.0, and since uap-core is the canonical regex definition, it affects all downstream implementations across multiple languages (Python, Node.js, PHP, etc.). The fix was released in version 0.6.0 and involved rewriting problematic regex patterns to avoid backtracking.

Affected products

  • UA-Parser uap-core before 0.6.0

Timeline

  • 2018-07-30: disclosed: Issue reported on GitHub
  • 2019-03-06: advisory: GHSA published
  • 2019: patched: Fixed in version 0.6.0

References

Related threats