PatchSiren

faisalman CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM faisalman CVE published 2026-07-14

CVE-2026-48125

A JavaScript library called UAParser.js, used for detecting browsers, operating systems, CPUs, and devices from user-agent data, had a regular expression denial-of-service vulnerability. This issue existed from version 2.0.1 until 2.0.10 when using the Client Hints API. An attacker could cause excessive CPU time by sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).wit [truncated]