Skip to content

Request to Resolve CVE-2021-21317 (ReDoS Vulnerability) in Commit f7f5a2f Used by Statsig SDK #97

@nhphuongltv

Description

@nhphuongltv

Hi team,

We're currently using the Statsig Go SDK, which depends on ua-parser/uap-go at commit f7f5a2f. This version is flagged by Snyk and other scanners for the following vulnerability:

I noticed that the Statsig team previously submitted PR to address this issue in Statsig Go SDK, but the vulnerability still appears unresolved in the current commit used by the SDK.

To ensure compliance and security, we kindly request that this CVE be properly resolved and a patched version be released. Please also consider looping in tore-statsig from the Statsig team, as our company is actively working with him on Statsig integration.

Thank you for your attention to this issue!

Best regards, Phuong Nguyen, AXON INC.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions