CVE-2017-16086
ReDoS via long UserAgent header in ua-parser
EPSS 9.2%
Description
Affected versions of `ua-parser` are vulnerable to regular expression denial of service when given a specially crafted `User-Agent` header. ## Recommendation No patch is currently available for this vulnerability. The best mitigation is currently to avoid using this package, using a different, functionally equivalent package such as [useragent](https://www.npmjs.com/package/useragent).
How to fix CVE-2017-16086
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/ua-parser—no fix listed
Is CVE-2017-16086 being exploited?
Moderate — EPSS is 9.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, <= 0.3.5