CVE Vulnerabilities

CVE-2022-25927

Inefficient Regular Expression Complexity

Published: Jan 26, 2023 | Modified: Jun 17, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
Ua-parser-jsUa-parser-js_project0.7.30 (including)0.7.33 (excluding)
Ua-parser-jsUa-parser-js_project0.8.1 (including)1.0.33 (excluding)
Red Hat Migration Toolkit for Containers 1.7RedHatrhmtc/openshift-migration-ui-rhel8:v1.7.8-5*
Node-ua-parser-jsUbuntubionic*
Node-ua-parser-jsUbuntufocal*
Node-ua-parser-jsUbuntukinetic*
Node-ua-parser-jsUbuntulunar*
Node-ua-parser-jsUbuntumantic*
Node-ua-parser-jsUbuntuoracular*
Node-ua-parser-jsUbuntuplucky*
Node-ua-parser-jsUbuntuquesting*

Potential Mitigations

References