Medium severity5.3NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-25927
CVE-2022-25927
Description
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ua-parser-jsnpm | >= 0.7.30, < 0.7.33 | 0.7.33 |
ua-parser-jsnpm | >= 0.8.0, < 1.0.33 | 1.0.33 |
Affected products
2- ua-parser-js/ua-parser-jsdescription
Patches
Vulnerability mechanics
References
5- github.com/faisalman/ua-parser-js/commit/a6140a17dd0300a35cfc9cff999545f267889411nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-UAPARSERJS-3244450nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-fhg7-m89q-25r3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25927ghsaADVISORY
- github.com/faisalman/ua-parser-js/security/advisories/GHSA-fhg7-m89q-25r3ghsaWEB
News mentions
0No linked articles in our index yet.