The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ua-parser-js | Ua-parser-js_project | * | 0.7.23 (excluding) |
| Node-ua-parser-js | Ubuntu | bionic | * |
| Node-ua-parser-js | Ubuntu | esm-apps/bionic | * |
| Node-ua-parser-js | Ubuntu | esm-apps/focal | * |
| Node-ua-parser-js | Ubuntu | focal | * |
| Node-ua-parser-js | Ubuntu | groovy | * |
| Node-ua-parser-js | Ubuntu | trusty | * |