CVE-2017-16030
HIGH 7.5EPSS 1.2%
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 1.16% chance of exploitation in the next 30 days, 65th percentile
- Published
- 2018-06-04
- Updated
- 2024-09-17
Proof-of-concept exploits (1)
- ossf-cve-benchmark/CVE-2017-160300★ · 2020-12-08