Skip to main content

Vendor/product archive

ua-parser-js_project / ua-parser-js CVEs

Beta · best-effort

6 CVEs tagged to ua-parser-js_project / ua-parser-js0 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-48125

Published Jul 14, 2026

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2022-25927

Published Jan 26, 2023

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() func…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-4229

Published May 24, 2022

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27292

Published Mar 17, 2021

ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1