CVE-2017-16086: Ua-Parser Project Ua-Parser

High severity, CVSS 7.5. EPSS: 9.2% chance of exploitation in the next 30 days.

ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.

Affected products

Published 2018-06-07. Last modified 2026-06-17.