Junglewise Threat Intelligence

CVE-2020-26311: useragent Regular Expression Denial of Service

CVE-2020-26311 · Severity: low · CVSS 3.1 · Published 2024-10-26

Vendors: npm.

Executive brief

useragent is a Node.js library that parses user-agent strings from web browsers and clients to identify device, browser, and operating system information. The library contains regular expressions vulnerable to ReDoS (Regular Expression Denial of Service), allowing an attacker to craft a malicious user-agent string that causes excessive CPU consumption and application hangs, potentially disrupting service availability for legitimate users.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS, CWE-1333) affecting regular expressions in the useragent library used for parsing user-agent strings. The vulnerable regexes contain nested quantifiers that cause catastrophic backtracking when processing specially crafted input containing repeated characters. An attacker can exploit this by providing a malicious user-agent string (e.g., containing 30,000+ repeated characters) that triggers excessive backtracking during parsing, consuming CPU resources and causing denial of service. All versions up to and including 2.3.0 are affected. A patch is available via commit 4c3ee79, though no official release version with the fix is specified in the advisory.

Affected products

  • 3rd-Eden useragent all versions up to 2.3.0

Timeline

  • 2020-11-30: disclosed: Security researcher initiated contact with maintainers
  • 2020: patched: Fix available via commit 4c3ee79358bea72d88fe78ac98f4f861db40b89b
  • 2024-10-26: advisory: GHSA advisory published

References

Related threats