Executive brief
ua-parser-js is a JavaScript library used to parse User-Agent HTTP headers and identify browser and device information. A maliciously crafted User-Agent header can trigger excessive processing in the library's regular expression engine, causing the application to hang or consume resources until the request times out. This can lead to denial of service attacks against web applications using vulnerable versions of the library.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) condition in ua-parser-js versions 0.7.14 through 0.7.23. The vulnerable regular expression pattern exhibits catastrophic backtracking when processing certain malicious User-Agent strings, causing the parsing operation to hang for an extended period. The attack requires only network-level access to send a crafted HTTP request with a malicious User-Agent header; no authentication or user interaction is required. An attacker can leverage this to exhaust server resources and disrupt service availability. The vulnerability was fixed in version 0.7.24.
Affected products
- faisalman ua-parser-js 0.7.14 through 0.7.23
Timeline
- 2021-03-17: disclosed: NVD publication date
- 2021-05-06: advisory: GHSA advisory published
- 2021-03-22: patched: Fix committed to repository (version 0.7.24)