PatchSiren

browserslist CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH browserslist CVE published 2026-08-11

CVE-2026-73089

CVE-2026-73089 is a high-severity vulnerability in the Browserslist configuration tool, which can cause a denial-of-service condition by influencing repeated browserslist() query values, leading to linear memory growth and an out-of-memory process crash. The issue is fixed in version 4.28.7. Defenders should assess exposure and prioritize updating Browserslist to version 4.28.7 or later. The vulnerability [truncated]

HIGH browserslist CVE published 2026-08-11

CVE-2026-73088

CVE-2026-73088 is a high-severity vulnerability in the Browserslist configuration tool. It allows an attacker to cause a TypeError or modify the prototype of a returned object by processing untrusted data with an unguarded loop and plain-object bracket access. The issue is fixed in version 4.28.7. This vulnerability affects Browserslist configurations and requires verification and update to prevent potent [truncated]