{"id":"GHSA-pcqq-5962-hvcw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-pcqq-5962-hvcw","summary":"Denial of Service in uap-core when processing crafted User-Agent strings","details":"### Impact\nSome regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.\n\n### Patches\nPlease update `uap-ruby` to &gt;= v2.6.0\n\n### For more information\nhttps://github.com/ua-parser/uap-core/security/advisories/GHSA-cmcx-xhr8-3w9p\n\nReported in `uap-core` by Ben Caller @bcaller","published":"2020-03-10T18:02:49Z","modified":"2025-05-22T17:55:09.602571Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"user_agent_parser","fixedVersion":"2.6.0"}],"fix":{"url":"https://github.com/ua-parser/uap-ruby/commit/2bb18268f4c5ba7d4ba0e21c296bf6437063da3a","label":"ua-parser/uap-ruby@2bb1826"},"references":[{"type":"WEB","url":"https://github.com/ua-parser/uap-ruby/security/advisories/GHSA-pcqq-5962-hvcw"},{"type":"WEB","url":"https://github.com/ua-parser/uap-ruby/commit/2bb18268f4c5ba7d4ba0e21c296bf6437063da3a"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/user_agent_parser/GHSA-pcqq-5962-hvcw.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-05-22T17:55:09.602571Z"}}