All fingerprinting is a vulnerability, unless the client opts-in.
The opt in checkbox is labeled "Enable Javascript"
https://fingerprint.com/blog/disabling-javascript-wont-stop-...
https://github.com/jonasstrehle/supercookie