A AegiFlow
HIGHCVSS 7.5EPSS 0.5%

CVE-2026-73089

CVE-2026-73089 updated by NVD

Published
2026-09-01
Modified
2026-09-21
EPSS percentile
40%
Sources
github-advisory, nvd, osv

Summary

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since ` - - ` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmbrowserslist4.28.7
npmbrowserslist4.28.7

Remediation: Upgrade to 4.28.7 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

Includes data from OSV.dev.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.