StackRadar

CVE-2021-27292

High

Advisory

Published 6 May 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.034
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

Regular Expression Denial of Service (ReDoS) in ua-parser-js

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
ua-parser-jsnpm0.7.17, 0.7.19, 0.7.20, 0.7.21+2 more0.7.2411
OSV records
GHSA-78cj-fxph-m83p

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
ua-parser-js@0.7.17
0.7.24

Open the chart page →

9,261
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ua-parser-js@0.7.20
0.7.24

Open the chart page →

6,868
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ua-parser-js@0.7.23
0.7.24

Open the chart page →

17,896
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
ua-parser-js@0.7.17
0.7.24

Open the chart page →

5,300
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
ua-parser-js@0.7.17
0.7.24

Open the chart page →

25,443
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
ua-parser-js@0.7.19
0.7.24

Open the chart page →

29,901
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ua-parser-js@0.7.17
0.7.24

Open the chart page →

11,174
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
ua-parser-js@0.7.21
0.7.24

Open the chart page →

2,689
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
ua-parser-js@0.7.19
0.7.24

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ua-parser-js@0.7.21
0.7.24

Open the chart page →

3,651
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
ua-parser-js@0.7.23
0.7.24

Open the chart page →

4,647
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-27292.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
ua-parser-js@0.7.22
0.7.24

Open the chart page →

27,465

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs-webui:2.7.5fbd10c017541
ua-parser-js@0.7.17
0.7.24
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
ua-parser-js@0.7.19
0.7.24
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ua-parser-js@0.7.17
0.7.24
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ua-parser-js@0.7.23
0.7.24
1
daskdev/dask-notebook:1.1.0052630f5ca04
ua-parser-js@0.7.19
0.7.24
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ua-parser-js@0.7.20
0.7.24
1
lavandadelpatio/frontend:latest501c3f31e0bc
ua-parser-js@0.7.21
0.7.24
1
linuxserver/cloud9:latest45c5fe102ff3
ua-parser-js@0.7.22
0.7.24
1
thelounge/thelounge:4.2.0-alpine639978459c3a
ua-parser-js@0.7.21
0.7.24
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
ua-parser-js@0.7.23
0.7.24
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
ua-parser-js@0.7.17
0.7.24
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.