← back
CVE-2017-16086CWE-400

CVE-2017-16086

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 9.2%
exploitation probability
9.2%top 5% of all CVEs
observed exploitation
nono source reports it
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.