Executive brief
UA-Parser is a widely-used library that identifies browser and device types from HTTP User-Agent headers. A flaw in its regular expression patterns allows attackers to craft malicious User-Agent strings with long digit sequences, causing the parsing logic to hang and consume CPU resources. This can be exploited remotely to degrade or disable services that depend on uap-core for user agent detection.
Technical details
This is a Regular Expression Denial of Service (ReDoS) vulnerability in the regex.yaml pattern definitions used by UA-Parser uap-core. The vulnerable regex patterns (such as `^(.*)/(\d+)\.?(\d+)?\.?(\d+)?\.?(\d+)? CFNetwork`) employ optional quantifiers and alternation that cause catastrophic backtracking when matched against a long string of digits. An attacker can trigger excessive CPU consumption by setting the User-Agent HTTP header to a value containing repeated digits, causing the regex engine to hang during parsing. The vulnerability affects all versions prior to 0.6.0, and since uap-core is the canonical regex definition, it affects all downstream implementations across multiple languages (Python, Node.js, PHP, etc.). The fix was released in version 0.6.0 and involved rewriting problematic regex patterns to avoid backtracking.
Affected products
- UA-Parser uap-core before 0.6.0
Timeline
- 2018-07-30: disclosed: Issue reported on GitHub
- 2019-03-06: advisory: GHSA published
- 2019: patched: Fixed in version 0.6.0