{"id":"GHSA-pcqq-5962-hvcw","summary":"Denial of Service in uap-core when processing crafted User-Agent strings","details":"### Impact\nSome regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.\n\n### Patches\nPlease update `uap-ruby` to &gt;= v2.6.0\n\n### For more information\nhttps://github.com/ua-parser/uap-core/security/advisories/GHSA-cmcx-xhr8-3w9p\n\nReported in `uap-core` by Ben Caller @bcaller","modified":"2025-05-22T17:55:09.602571Z","published":"2020-03-10T18:02:49Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-03-10T16:48:58Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/ua-parser/uap-ruby/security/advisories/GHSA-pcqq-5962-hvcw"},{"type":"WEB","url":"https://github.com/ua-parser/uap-ruby/commit/2bb18268f4c5ba7d4ba0e21c296bf6437063da3a"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/user_agent_parser/GHSA-pcqq-5962-hvcw.yml"}],"affected":[{"package":{"name":"user_agent_parser","ecosystem":"RubyGems","purl":"pkg:gem/user_agent_parser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"versions":["0.1.0","0.1.1","0.1.2","1.0.0","1.0.1","1.0.2","2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.2.0","2.3.0","2.3.1","2.3.2","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-pcqq-5962-hvcw/GHSA-pcqq-5962-hvcw.json"}}],"schema_version":"1.9.0"}