Hi @nlf
The useragent package has security vulnerability wrt. regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS) as highlighted here.
This package is not maintained anymore which is why updating to a different dependency or its forks may help address this vulnerability. Additionally, a workaround is mentioned here.
@channel - Please share recommendations on alternate CSP plugins for hapi that do not depend on useragent.
Thanks,
Sana