CVE-2021-27292: Uncontrolled Resource Consumption
(updated )
ua-parser-js uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent
header, ua-parser-js will get stuck processing it for an extended period of time.
References
Detect and mitigate CVE-2021-27292 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →