{"id":"GHSA-78hm-5hjw-58mh","summary":"ua-parser/uap-php ReDoS vulnerability","details":"A regex expression in ua-parser/uap-php could lead to a ReDoS vulnerability in versions prior to 3.8.0.","modified":"2024-12-04T05:45:02.512198Z","published":"2024-06-07T22:14:49Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-07T22:14:49Z","nvd_published_at":null,"cwe_ids":["CWE-1333"]},"references":[{"type":"WEB","url":"https://github.com/ua-parser/uap-core/pull/363"},{"type":"WEB","url":"https://github.com/ua-parser/uap-core/commit/156f7e12b215bddbaf3df4514c399d683e6cdadc"},{"type":"WEB","url":"https://github.com/ua-parser/uap-php/commit/947f80b39130c83a3d1c75900ac1b58828ed8aef"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ua-parser/uap-php/2018-12-14.yaml"},{"type":"PACKAGE","url":"https://github.com/ua-parser/uap-php"}],"affected":[{"package":{"name":"ua-parser/uap-php","ecosystem":"Packagist","purl":"pkg:composer/ua-parser/uap-php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.0"}]}],"versions":["v3.4.0","v3.4.1","v3.4.2","v3.4.3","v3.4.4","v3.4.5","v3.4.6","v3.4.7","v3.5.0","v3.6.0","v3.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-78hm-5hjw-58mh/GHSA-78hm-5hjw-58mh.json"}}],"schema_version":"1.9.0"}