Executive brief
ua-parser-js is a popular JavaScript library used to parse user-agent strings from web browsers and mobile devices. A flaw in its regular expression matching logic can be exploited to cause the application to hang or consume excessive CPU resources when processing specially crafted user-agent strings, potentially disrupting service availability.
Technical details
This vulnerability is a Regular Expression Denial of Service (ReDoS) in ua-parser-js versions prior to 0.7.22. The root cause is a poorly constructed regular expression used to parse Redmi phones and Mi Pad tablets in user-agent strings, which exhibits catastrophic backtracking when processing certain input patterns. The vulnerability is network-accessible and requires no authentication or user interaction; an attacker can send malicious user-agent headers to trigger excessive regex evaluation. Successful exploitation causes denial of service by exhausting CPU resources. The fix was released in version 0.7.22 and is documented in commit 233d3ba.
Affected products
- faisalman ua-parser-js before 0.7.22
Timeline
- 2021-05-07: disclosed: Advisory published
- 2020: patched: Fix available in version 0.7.22