{"id":"GHSA-fhg7-m89q-25r3","summary":"ReDoS Vulnerability in ua-parser-js version","details":"### Description:\nA regular expression denial of service (ReDoS) vulnerability has been discovered in `ua-parser-js`.\n\n### Impact:\nThis vulnerability bypass the library's `MAX_LENGTH` input limit prevention. By crafting a very-very-long user-agent string with specific pattern, an attacker can turn the script to get stuck processing for a very long time which results in a denial of service (DoS) condition.\n\n### Affected Versions:\nFrom version `0.7.30` to before versions `0.7.33` / `1.0.33`.\n\n### Patches:\nA patch has been released to remove the vulnerable regular expression, update to version `0.7.33` / `1.0.33` or later.\n\n### References:\n[Regular expression Denial of Service - ReDoS](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS)\n\n### Credits:\nThanks to @Snyk who first reported the issue.","aliases":["CVE-2022-25927"],"modified":"2025-10-17T16:52:22Z","published":"2023-01-24T15:36:32Z","database_specific":{"github_reviewed_at":"2023-01-24T15:36:32Z","nvd_published_at":"2023-01-26T21:15:00Z","cwe_ids":["CWE-1333","CWE-400"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/faisalman/ua-parser-js/security/advisories/GHSA-fhg7-m89q-25r3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25927"},{"type":"WEB","url":"https://github.com/faisalman/ua-parser-js/commit/a6140a17dd0300a35cfc9cff999545f267889411"},{"type":"PACKAGE","url":"https://github.com/faisalman/ua-parser-js"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-UAPARSERJS-3244450"}],"affected":[{"package":{"name":"ua-parser-js","ecosystem":"npm","purl":"pkg:npm/ua-parser-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.7.30"},{"fixed":"0.7.33"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-fhg7-m89q-25r3/GHSA-fhg7-m89q-25r3.json"}},{"package":{"name":"ua-parser-js","ecosystem":"npm","purl":"pkg:npm/ua-parser-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.8.0"},{"fixed":"1.0.33"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-fhg7-m89q-25r3/GHSA-fhg7-m89q-25r3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}