7.5
CVSSv3

CVE-2022-25927

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Versions of the package ua-parser-js from 0.7.30 and prior to 0.7.33, from 0.8.1 and prior to 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ua-parser-js project ua-parser-js

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Versions of the package ua-parser-js from 0730 and before 0733, from 081 and before 1033 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function ...