Skip to content

Security Vulnerability with useragent package #52

@sana-fathima-mck

Description

@sana-fathima-mck

Hi @nlf

The useragent package has security vulnerability wrt. regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS) as highlighted here.
This package is not maintained anymore which is why updating to a different dependency or its forks may help address this vulnerability. Additionally, a workaround is mentioned here.
@channel - Please share recommendations on alternate CSP plugins for hapi that do not depend on useragent.

Thanks,
Sana

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions