Regular Expression Denial of Service (ReDoS)
Published Sep 16, 2020
7.5
HIGHCVSS 3.1
EPSS 4.48%
Description
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
Affected products
- Vendor n/a Product UA-Parser-JS Defaultn/a
- Version unspecifiedStatusaffectedConstraints<0.7.22
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | UA-Parser-JS | n/a |
|
Configuration 1
- < 0.7.22
Configuration 2
- 1.7.0
No data.
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.7-1.el8ev
Fixed · RHSA-2021:2865
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.7.2-1.el8ev
Fixed · RHSA-2021:4626
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-all-in-one-rhel7
Fix deferred
Distributed Tracing Jaeger 1
distributed-tracing/jaeger-query-rhel7
Fix deferred
OpenShift Service Mesh 1
servicemesh-grafana
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
nodejs-ua-parser-js
Fix deferred
Red Hat OpenShift Container Platform 3.11
kibana
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Not affected
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Fix deferred
Red Hat Storage 3
grafana
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.7-1.el8ev | Fixed | RHSA-2021:2865 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.7.2-1.el8ev | Fixed | RHSA-2021:4626 |
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-all-in-one-rhel7 | Fix deferred | n/a |
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-query-rhel7 | Fix deferred | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | nodejs-ua-parser-js | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Fix deferred | n/a |
| Red Hat Storage 3 | grafana | Fix deferred | n/a |
ua-parser-js
npm
Introduced 0 Fixed 0.7.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ua-parser-js | 0 | 0.7.22 |
Remediation
Red Hat statement
Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 4.48% (0.04483) | 91.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.48% (0.04483) | 90.21th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.73% (0.01729) | 80.76th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.84% (0.21842) | 93.09th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.73% (0.01729) | 81.20th | v4 (v2025.03.14) |
| Dec 17, 2024 | 0.29% (0.00291) | 68.62th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.39% (0.00385) | 72.38th | v3 (v2023.03.01) |
| Jun 2, 2023 | 0.39% (0.00385) | 69.20th | v3 (v2023.03.01) |
| Apr 23, 2023 | 0.34% (0.00338) | 66.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.29% (0.00290) | 64.10th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.18% (0.07176) | 80.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.60% (0.06599) | 83.03th | v1 |
| Jan 6, 2022 | 6.60% (0.06599) | 82.86th | v1 |
| Sep 1, 2021 | 1.55% (0.01550) | 73.01th | v1 |
| Jul 21, 2021 | 1.55% (0.01550) | 0.00th | v1 |
| Apr 14, 2021 | 1.29% (0.01294) | 0.00th | v1 |
References (10)
- https://access.redhat.com/security/cve/CVE-2020-7733 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879733 Issue Tracking
- https://github.com/advisories/GHSA-662x-fhqg-9p8v Advisory
- https://github.com/faisalman/ua-parser-js/commit/233d3bae22a795153a7e6638887ce159c63e557d x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7733
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-674666 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-674665 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7733
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7733 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1879733 | Issue Tracking | |
| https://github.com/advisories/GHSA-662x-fhqg-9p8v | Advisory | |
| https://github.com/faisalman/ua-parser-js/commit/233d3bae22a795153a7e6638887ce159c63e557d | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7733 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-674666 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-674665 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7733 | ||
| https://www.oracle.com//security-alerts/cpujul2021.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.