VYPR
Medium severity5.3NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026

CVE-2022-25927

CVE-2022-25927

Description

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ua-parser-jsnpm
>= 0.7.30, < 0.7.330.7.33
ua-parser-jsnpm
>= 0.8.0, < 1.0.331.0.33

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.