Ua Parser Project maintains a narrowly scoped user-agent parsing library that is widely embedded across web applications and analytics platforms for device and browser identification. The modest vulnerability history centers on the ua_parser product itself, with the observed weakness classes and structural exposure reflecting the parsing demands inherent to processing client-supplied user-agent strings. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ua Parser Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16086HIGH ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent h | Jun 7, 2018 | 7.5 | 34 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ua Parser Project.
Media articles that mention a CVE ID that affects a product developed by Ua Parser Project — matched by CVE ID, not by vendor name.