<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:29:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337880</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337880</link>
      <description>EUVD-2026-337880</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337880</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48125</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48125</link>
      <description>&lt;p&gt;UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48125</guid>
    </item>
    <item>
      <title>GHSA-9h5v-pfqq-x599 — UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9h5v-pfqq-x599</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ua-parser-js&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A regular expression denial-of-service (ReDoS) vulnerability has been discovered in `ua-parser-js` when using the Client Hints API. By sending a crafted `Sec-CH-UA-Model` header to an application that calls `UAParser(headers).withClientHints()`, an attacker can cause the parser to spend excessive CPU time due to catastrophic backtracking in the device [regex](https://github.com/faisalman/ua-parser-js/blob/2.0.9/src/main/ua-parser.js#L615):&lt;/p&gt;
&lt;p&gt;```js
/ ([\w ]+) miui\/v?\d/i
```&lt;/p&gt;
&lt;p&gt;Unlike when using the `User-Agent` value, which has a hard limit of `UA_MAX_LENGTH = 500`, when using Client Hints, values are copied without a length limit before being passed into regex parsing.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const { UAParser } = require(&amp;#39;ua-parser-js&amp;#39;);&lt;/p&gt;
&lt;p&gt;const headers = {
  &amp;#39;sec-ch-ua-platform&amp;#39;: &amp;#39;&amp;#34;Android&amp;#34;&amp;#39;,
  &amp;#39;sec-ch-ua-mobile&amp;#39;: &amp;#39;?1&amp;#39;,
  &amp;#39;sec-ch-ua-model&amp;#39;: &amp;#39;&amp;#34;&amp;#39; + &amp;#39;A &amp;#39;.repeat(25000) + &amp;#39;&amp;#34;&amp;#39;
};&lt;/p&gt;
&lt;p&gt;const t0 = process.hrtime.bigint();
UAParser(headers).withClientHints();
const ms = Number(process.hrtime.bigint() - t0) / 1e6;&lt;/p&gt;
&lt;p&gt;if (ms &amp;gt; 100) {
  console.log(&amp;#39;Potential ReDoS&amp;#39;);
}
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability allows an unauthenticated attacker to trigger a denial-of-service condition in any __server-side__ application that uses `UAParser(headers).withClientHints()`. A single request with a ~32,000-character model value can consume over 400ms of CPU time, with parsing time growing polynomially with input length. The impact is __availability__ only, there is no confidentiality or integrity impa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ua-parser-js&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A regular expression denial-of-service (ReDoS) vulnerability has been discovered in `ua-parser-js` when using the Client Hints API. By sending a crafted `Sec-CH-UA-Model` header to an application that calls `UAParser(headers).withClientHints()`, an attacker can cause the parser to spend excessive CPU time due to catastrophic backtracking in the device [regex](https://github.com/faisalman/ua-parser-js/blob/2.0.9/src/main/ua-parser.js#L615):&lt;/p&gt;
&lt;p&gt;```js
/ ([\w ]+) miui\/v?\d/i
```&lt;/p&gt;
&lt;p&gt;Unlike when using the `User-Agent` value, which has a hard limit of `UA_MAX_LENGTH = 500`, when using Client Hints, values are copied without a length limit before being passed into regex parsing.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const { UAParser } = require(&amp;#39;ua-parser-js&amp;#39;);&lt;/p&gt;
&lt;p&gt;const headers = {
  &amp;#39;sec-ch-ua-platform&amp;#39;: &amp;#39;&amp;#34;Android&amp;#34;&amp;#39;,
  &amp;#39;sec-ch-ua-mobile&amp;#39;: &amp;#39;?1&amp;#39;,
  &amp;#39;sec-ch-ua-model&amp;#39;: &amp;#39;&amp;#34;&amp;#39; + &amp;#39;A &amp;#39;.repeat(25000) + &amp;#39;&amp;#34;&amp;#39;
};&lt;/p&gt;
&lt;p&gt;const t0 = process.hrtime.bigint();
UAParser(headers).withClientHints();
const ms = Number(process.hrtime.bigint() - t0) / 1e6;&lt;/p&gt;
&lt;p&gt;if (ms &amp;gt; 100) {
  console.log(&amp;#39;Potential ReDoS&amp;#39;);
}
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This vulnerability allows an unauthenticated attacker to trigger a denial-of-service condition in any __server-side__ application that uses `UAParser(headers).withClientHints()`. A single request with a ~32,000-character model value can consume over 400ms of CPU time, with parsing time growing polynomially with input length. The impact is __availability__ only, there is no confidentiality or integrity impa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9h5v-pfqq-x599</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48125</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48125</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ua-parser-js, Ubuntu:20.04:LTS: node-ua-parser-js, Ubuntu:22.04:LTS: node-ua-parser-js, Ubuntu:24.04:LTS: node-ua-parser-js, Ubuntu:26.04:LTS: node-ua-parser-js&lt;/p&gt;
&lt;p&gt;UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ua-parser-js, Ubuntu:20.04:LTS: node-ua-parser-js, Ubuntu:22.04:LTS: node-ua-parser-js, Ubuntu:24.04:LTS: node-ua-parser-js, Ubuntu:26.04:LTS: node-ua-parser-js&lt;/p&gt;
&lt;p&gt;UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48125</guid>
    </item>
  </channel>
</rss>
