Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
References
Link Resource
https://nodesecurity.io/advisories/312 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2018-04-26T00:00:00

Updated: 2018-06-04T18:57:01

Reserved: 2017-10-29T00:00:00


Link: CVE-2017-16030

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-06-04T19:29:01.677

Modified: 2019-10-09T23:24:38.110


Link: CVE-2017-16030

JSON object: View

cve-icon Redhat Information

No data.