Executive brief
ua-parser-js is a JavaScript library that parses user-agent strings to identify browsers and devices. A regular expression flaw allows attackers to craft specially-patterned, extremely long user-agent strings that cause the parser to hang indefinitely, effectively disabling any application that relies on it for parsing user-agent data. This can result in application unavailability and degraded user experience.
Technical details
A regular expression denial of service (ReDoS) vulnerability exists in ua-parser-js versions 0.7.30–0.7.32 and 0.8.0–1.0.32. The vulnerability bypasses the library's MAX_LENGTH input validation due to an inefficient regular expression (CWE-1333) that exhibits exponential worst-case complexity. An attacker can send a specially crafted user-agent string with a specific pattern that triggers catastrophic backtracking in the regex engine, consuming excessive CPU and causing the application to hang. The attack vector is network-based with no authentication or user interaction required. Patches are available in versions 0.7.33 and 1.0.33, which remove the vulnerable regular expression.
Affected products
- faisalman ua-parser-js 0.7.30 to before 0.7.33, 0.8.0 to before 1.0.33
Timeline
- 2023-01-24: disclosed
- 2023-01-24: patched: Patches released for versions 0.7.33 and 1.0.33