CVE-2020-26311
Oct. 28, 2024, 1:58 p.m.
Tags
Product(s) Impacted
Useragent for Node.js
Description
Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.
Weaknesses
CWE-1333
Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CWE ID: 1333Date
Published: Oct. 26, 2024, 9:15 p.m.
Last Modified: Oct. 28, 2024, 1:58 p.m.
Status : Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security-advisories@github.com
References
security-advisories@github.com
security-advisories@github.com