CVE-2026-48125
MEDIUMUAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
Title source: cnaDescription
UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/faisalman/ua-parser-js/security/advisories/GHSA-9h5v-pfqq-x599
X_Refsource_Misc x_refsource_misc
https://github.com/faisalman/ua-parser-js/commit/90354d3458495628b1d3ba68a9d76673e6d14fc5
X_Refsource_Misc x_refsource_misc
https://github.com/faisalman/ua-parser-js/releases/tag/2.0.10
Scores
CVSS v3
5.3
EPSS
0.0037
EPSS Percentile
29.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
CWE-400
Status
published
Products (1)
faisalman/ua-parser-js
>= 2.0.1, < 2.0.10
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026