CVE-2026-106104
Received Received - Intake

Quasar Framework SSR Request Header ReDoS Vulnerability

Vulnerability report for CVE-2026-106104, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() passed an unbounded User-Agent request header to getMatch() in ui/src/plugins/platform/Platform.js, whose browser-detection expressions combined greedy captures with repeated unbounded scans. Platform belongs to autoInstalledPlugins, so this parsing occurs before routing for every SSR request. A crafted unauthenticated request containing repeated version tokens without a terminating Safari token causes super-linear backtracking and blocks the Node.js event loop, delaying every other SSR request. SPA, PWA, Electron, Cordova, Capacitor, browser-extension, and static-site-generation targets are not affected because they do not parse an attacker-controlled request header through this path. This issue is fixed in version 2.23.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quasarframework quasar < 2.23.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quasar Framework before 2.23.3 has a vulnerability in Platform.parseSSR() where an unbounded User-Agent header triggers super-linear backtracking in browser-detection expressions. This causes delays in processing SSR requests by blocking the Node.js event loop.

Detection Guidance

This vulnerability is specific to Quasar Framework versions before 2.23.3 and involves super-linear backtracking due to crafted User-Agent headers. Detection requires checking the Quasar Framework version in use. If you are running a version prior to 2.23.3, the system is vulnerable. No specific network or system commands are provided in the context to detect this issue directly.

Impact Analysis

An attacker can send crafted requests to slow down or block server-side rendering (SSR) for all users, causing delays in page loads and potentially disrupting service availability.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by causing denial-of-service conditions due to event loop blocking, which may disrupt availability of services handling personal or health data. Unbounded request processing could lead to prolonged downtime, violating requirements for timely access to critical systems under these regulations.

Mitigation Strategies

Immediately upgrade Quasar Framework to version 2.23.3 or later to address the vulnerability. This version fixes the issue with Platform.parseSSR() and unbounded User-Agent header processing. Ensure all dependencies and applications using Quasar Framework are updated to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106104. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart