Debian Package Tracker
Register | Log in
Subscribe

node-ua-parser-js

Lightweight JavaScript-based user-agent string parser

Choose email to subscribe with

general
  • source: node-ua-parser-js (main)
  • version: 0.8.1+ds+~0.7.36-3
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.7.24+ds-1
  • oldstable: 0.8.1+ds+~0.7.36-3
  • stable: 0.8.1+ds+~0.7.36-3
  • testing: 0.8.1+ds+~0.7.36-3
  • unstable: 0.8.1+ds+~0.7.36-3
versioned links
  • 0.7.24+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.8.1+ds+~0.7.36-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-ua-parser-js
action needed
A new upstream version is available: 2.0.10+~0.7.39 high
A new upstream version 2.0.10+~0.7.39 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2026-07-26 09:00
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-48125: UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
Created: 2026-07-16 Last update: 2026-07-16 18:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-48125: UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
Created: 2026-07-16 Last update: 2026-07-16 18:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-48125: UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
Created: 2026-07-16 Last update: 2026-07-16 18:00
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2026-48125: UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
1 issue postponed or untriaged:
  • CVE-2022-25927: (needs triaging) Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
Created: 2026-07-16 Last update: 2026-07-16 18:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-48125: UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.
Created: 2026-07-16 Last update: 2026-07-16 18:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2023-04-14] node-ua-parser-js 0.8.1+ds+~0.7.36-3 MIGRATED to testing (Debian testing watch)
  • [2023-04-09] Accepted node-ua-parser-js 0.8.1+ds+~0.7.36-3 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-11-23] node-ua-parser-js 0.8.1+ds+~0.7.36-2 MIGRATED to testing (Debian testing watch)
  • [2022-11-21] Accepted node-ua-parser-js 0.8.1+ds+~0.7.36-2 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2022-10-21] node-ua-parser-js 0.8.1+ds+~0.7.36-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-18] Accepted node-ua-parser-js 0.8.1+ds+~0.7.36-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-01-16] node-ua-parser-js 0.7.31+ds+~0.7.36-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-14] Accepted node-ua-parser-js 0.7.31+ds+~0.7.36-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-12-05] node-ua-parser-js 0.7.24+ds-2 MIGRATED to testing (Debian testing watch)
  • [2021-12-02] Accepted node-ua-parser-js 0.7.24+ds-2 (source) into unstable (Jonas Smedegaard)
  • [2021-03-25] node-ua-parser-js 0.7.24+ds-1 MIGRATED to testing (Debian testing watch)
  • [2021-03-20] Accepted node-ua-parser-js 0.7.24+ds-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2020-12-17] node-ua-parser-js 0.7.23+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-15] Accepted node-ua-parser-js 0.7.23+ds-1 (source) into unstable (Xavier Guimard)
  • [2020-09-19] node-ua-parser-js 0.7.22+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-17] Accepted node-ua-parser-js 0.7.22+ds-1 (source) into unstable (Xavier Guimard)
  • [2017-11-11] node-ua-parser-js 0.7.14-1 MIGRATED to testing (Debian testing watch)
  • [2017-11-01] Accepted node-ua-parser-js 0.7.14-1 (source all) into unstable, unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.8.1+ds+~0.7.36-3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing