Junglewise Threat Intelligence

CVE-2020-7793: ua-parser-js Regular Expression Denial of Service

CVE-2020-7793 · Severity: low · CVSS 3.1 · Published 2022-02-09

Technologies: ua-parser-js (npm). Vendors: npm.

Executive brief

ua-parser-js is a popular JavaScript library used to identify browser, engine, OS, and device details from user-agent strings. A vulnerability in how it processes these strings allows an attacker to send a specially crafted request that causes the system to consume excessive CPU resources. This can lead to a service slowdown or a complete crash, preventing legitimate users from accessing the application.

Technical details

The ua-parser-js library before version 0.7.23 contains multiple regular expressions susceptible to catastrophic backtracking. An attacker can exploit this by providing a malicious User-Agent string (e.g., containing long sequences of specific characters) that triggers exponential processing time in the regex engine. This is a Regular Expression Denial of Service (ReDoS) vulnerability (CWE-400). The attack can be executed remotely without authentication or user interaction. Successful exploitation results in high CPU exhaustion, leading to a Denial of Service (DoS) condition. The issue is fixed in version 0.7.23 by optimizing the affected regex patterns.

Affected products

  • faisalman ua-parser-js < 0.7.23

Timeline

  • 2020-10-29: disclosed: Vulnerability disclosed to maintainer
  • 2020-12-01: patched: Fix committed to repository
  • 2020-12-11: advisory: NVD published CVE-2020-7793

References

Related threats