Bug 2514195 (CVE-2026-73089)

Summary: CVE-2026-73089 browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, abrianik, abuckta, akostadi, alizardo, amasferr, amctagga, anpicker, anthomas, anujha, aoconnor, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, bniver, boliveir, brasmith, bstansbe, cdrage, cmah, cochase, dbruscin, dkuc, dlofthou, dmayorov, doconnor, dranck, drichtar, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, flucifre, fmariani, ggainey, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibolton, istudens, ivassile, iweiss, janstey, jchui, jfula, jhe, jhorak, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jraez, jtolenti, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, mbenjamin, mcarlett, mdellweg, mhackett, mhulan, mosmerov, mposolda, msvehla, mvyas, nboldt, ngough, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, osousa, pantinor, parichar, pberan, pcreech, pesilva, pgaikwad, pjindal, pmackay, psrna, ptisnovs, rchan, rhaigner, rhel-process-autobot, rjohnson, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, simaishi, slucidi, smallamp, sostapov, sseago, ssilvert, stcannon, sthorger, syedriko, tasato, tcunning, teagle, thjenkin, tmalecek, tsedmik, ttakamiy, vdosoudi, vereddy, veshanka, vmuzikar, watson-tool-maintainers, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Browserslist, a configuration tool for front-end development. An attacker can exploit this vulnerability by influencing repeated query values, leading to unbounded memory growth. This issue can cause the application to consume excessive memory, resulting in an out-of-memory process crash and a Denial of Service (DoS) for affected systems.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-11 17:13:11 UTC
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.