CVE-2022-25927

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/01/2023
Last modified:
01/04/2025

Description

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ua-parser-js_project:ua-parser-js:*:*:*:*:*:node.js:*:* 0.7.30 (including) 0.7.33 (excluding)
cpe:2.3:a:ua-parser-js_project:ua-parser-js:*:*:*:*:*:node.js:*:* 0.8.1 (including) 1.0.33 (excluding)