Bug 2515240 (CVE-2026-45819)

Summary: CVE-2026-45819 baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, abuckta, alizardo, amctagga, anpicker, anthomas, aoconnor, aruklets, aschwart, aszczucz, ataylor, bbrownin, bniver, boliveir, bparees, brasmith, cdrage, cmah, cochase, dbruscin, dkuc, doconnor, dranck, drichtar, dschmidt, eaguilar, ebaron, ehelms, ehugonne, flucifre, ggainey, gmeno, groman, hasun, jchui, jfula, jhe, jlanda, jmatsuok, jowilson, jpasqual, jtolenti, juwatts, jwong, kaycoth, kshier, ktsao, kvanderr, mbenjamin, mdellweg, mhackett, mhulan, mposolda, nboldt, nmoumoul, nyancey, oaljalju, omaciel, ometelka, orabin, osousa, pcreech, pjindal, psrna, ptisnovs, rchan, rhel-process-autobot, rmartinc, rushinde, sdawley, simaishi, smallamp, sostapov, ssilvert, stcannon, sthorger, syedriko, teagle, tmalecek, ttakamiy, vereddy, vmuzikar, watson-tool-maintainers, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in baseline-browser-mapping. This vulnerability allows an attacker to cause a denial of service by providing invalid or conflicting input parameters. The affected component improperly terminates the process instead of handling the input error gracefully, leading to immediate service disruption.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-13 11:43:42 UTC
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.