browserslist
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting browserslistpage 1 of 1
- CVE-2021-23364MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.16.52021-04-28
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
- CVE-2026-73088HIGHCVSS 7.5EG 7.5✓ Fixed in 4.28.72026-08-11
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() c…
- CVE-2026-73089HIGHCVSS 7.5EG 7.5✓ Fixed in 4.28.72026-08-11
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache…
Check whether browserslist is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for browserslist CVEs against the assets you own.
Start Free Scan →