Ua Parser Js Project maintains a lightweight, widely embedded JavaScript library for parsing user-agent strings, a function that appears across browser applications, server-side logging, and analytics platforms despite the project's narrow product scope. The observed vulnerability surface has centered on the library's parsing logic and regular-expression handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ua Parser Js Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4229HIGH A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading t | May 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-7733HIGH The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA. | Sep 16, 2020 | 7.5 | 26 | NO | NO |
CVE-2022-25927HIGH Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() funct | Jan 26, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-27292HIGH ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will g | Mar 17, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-7793HIGH The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). | Dec 11, 2020 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ua Parser Js Project.
Media articles that mention a CVE ID that affects a product developed by Ua Parser Js Project — matched by CVE ID, not by vendor name.