Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73088

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including proto, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

A flaw was found in Browserslist, a tool for sharing browser and Node.js versions. An attacker could provide specially crafted statistics data, which the tool processes without proper validation. This improper handling of untrusted data can lead to prototype pollution, potentially causing the application to crash and resulting in a denial of service.

Отчет

This is an Important vulnerability. The browserslist package, a front-end development tool, is vulnerable to prototype pollution when processing untrusted statistics data. This flaw can lead to a denial of service, as malicious input can crash applications that use the affected library. The impact is considered Important due to the potential for remote exploitation without authentication or user interaction, directly affecting service availability.

Меры по смягчению последствий

To reduce exposure, ensure that the browserslist tool processes only trusted browserslist-stats.json, opts.stats, and CLI --stats data. Avoid using the tool with untrusted input sources in development or build environments. If browserslist is integrated into automated pipelines, validate all input data originates from trusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4browserslistNot affected
Cryostat 4cryostat-openshift-console-plugin-npmAffected
Cryostat 4grafana-infinity-datasource-npmAffected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleAffected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorAffected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-console-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2514177browserslist: Browserslist: Prototype pollution leading to denial of service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
17 дней назад

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

CVSS3: 7.5
nvd
17 дней назад

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

CVSS3: 7.5
debian
17 дней назад

Browserslist is a configuration tool for sharing target browsers and N ...

suse-cvrf
10 дней назад

Security update for python-pytest-html

7.5 High

CVSS3

Уязвимость CVE-2026-73088