Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. ua-parser/uap-php
  4. ›
  5. GHSA-78hm-5hjw-58mh

GHSA-78hm-5hjw-58mh: ua-parser/uap-php ReDoS vulnerability

June 7, 2024

A regex expression in ua-parser/uap-php could lead to a ReDoS vulnerability in versions prior to 3.8.0.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/ua-parser/uap-php/2018-12-14.yaml
  • github.com/advisories/GHSA-78hm-5hjw-58mh
  • github.com/ua-parser/uap-core/commit/156f7e12b215bddbaf3df4514c399d683e6cdadc
  • github.com/ua-parser/uap-core/pull/363
  • github.com/ua-parser/uap-php
  • github.com/ua-parser/uap-php/commit/947f80b39130c83a3d1c75900ac1b58828ed8aef

Code Behaviors & Features

Detect and mitigate GHSA-78hm-5hjw-58mh with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.8.0

Fixed versions

  • 3.8.0

Solution

Upgrade to version 3.8.0 or above.

Weakness

  • CWE-1333: Inefficient Regular Expression Complexity

Source file

packagist/ua-parser/uap-php/GHSA-78hm-5hjw-58mh.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:11 +0000.