Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25927


Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.


Published

2023-01-26T21:15:32.107

Last Modified

2025-04-01T19:15:41.557

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-1333
  • Type: Primary
    CWE-1333
  • Type: Secondary
    CWE-1333

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ua-parser-js_project ua-parser-js < 0.7.33 Yes
Application ua-parser-js_project ua-parser-js < 1.0.33 Yes

References