CVE-2026-45819
Aliases:GHSA-w5vr-8v7q-w6rvCGA-8qp3-g3vp-mjp5CGA-cg44-8v7p-m8hvCGA-vpp5-r683-m668CGA-248f-hhwp-mhc5CGA-75x9-7wfw-h6hcCGA-fjgx-hxvw-f5cfCGA-frq9-hpm3-5wggCGA-gq3r-2hjv-2mm5CGA-mpcr-r329-m74mCGA-pmrp-w64h-qcgfCGA-wf84-wrj4-ch4fCGA-xc23-xqcg-3mc9CGA-xfxc-3fr6-4wx6CGA-3mf7-h6f3-j3vjCGA-63m2-hh8h-vx6pCGA-2r2h-5gh9-3w2vCGA-x98m-pj99-c5w4CGA-9766-gx7g-fhx9CGA-5q69-vw9w-rrf8CGA-c242-vm3x-vhpqCGA-h274-6mhv-6px8CGA-h5mp-w8p8-7cccCGA-j2cv-gw7c-24xmCGA-j6wp-g3gv-qmpmCGA-q36q-j957-3g5fCGA-q487-p6q2-c8vfCGA-9885-39cv-5c8wCGA-g53x-43jv-86j6CGA-8964-6rp9-2w39CGA-cfj2-vqwc-7736CGA-hgpg-566c-p2xr
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Deferred
Published: 13 Aug 2026, 11:03
Last modified:13 Aug 2026, 14:46
Vulnerability Summary
Overall Risk (default)
medium
26/100 CVSS Score
6.6 MEDIUM
v4.0 (cve.org)
EPSS Score
0.37% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Aug 2026, 11:03
Published
Vulnerability first disclosed
13 Aug 2026, 14:46
Last Modified
Vulnerability information updated
Description
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
- v4.0•MEDIUM•Score: 6.6CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
EPSS Trends
Current EPSS score: 0.37%• Percentile: 31%
Techniques & Countermeasures
- CWE-705•Incorrect Control Flow Scoping
The product does not properly return control flow to the proper location after it has completed a task or detected an unusual condition.
- CWE-755•Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
Affected Systems
- chainguard•airflow-2
all
- chainguard•airflow-core-2
all
- chainguard•argo-workflows-ui-4.0
< 4.0.11-r0
- chainguard•authentik-fips-2025.12
all
- chainguard•commercial-gitlab-rails-ee-19.1
all
- chainguard•commercial-gitlab-rails-ee-19.3
all
- chainguard•commercial-gitlab-rails-ee-fips-19.1
all
- chainguard•commercial-gitlab-rails-ee-fips-19.2
all
- chainguard•commercial-gitlab-rails-ee-fips-19.3
all
- chainguard•jupyter-base-notebook
all
- chainguard•kibana-8.19
all | < 8.19.21-r4
- chainguard•kibana-8.19-bitnami
all | < 8.19.21-r4
- chainguard•kibana-8.19-iamguarded
all
- chainguard•langfuse-3-compat
< 3.225.7-r6
- chainguard•langfuse-3-worker
all | < 3.225.7-r4
- chainguard•langfuse-fips-3-worker
all | < 3.225.7-r1
- wolfi•argo-workflows-ui-4.0
< 4.0.11-r0
- wolfi•jupyter-base-notebook
all
- wolfi•langfuse-3-compat
< 3.225.7-r6
- wolfi•langfuse-3-worker
all | < 3.225.7-r4
- Npm•baseline-browser-mapping
≥ 2.0.0, < 2.11.0
- web-platform-dx•baseline-browser-mapping
≥ 2.0.0, < 2.11.0
References (9)
- https://github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts#L142
- https://www.npmjs.com/package/baseline-browser-mapping
- https://github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes#diff-7ae45ad102eab3b6d7e7896acd08c427a9b25b346470d7bc6507b6481575d519
- https://nvd.nist.gov/vuln/detail/CVE-2026-45819
- https://github.com/web-platform-dx/baseline-browser-mapping/pull/137
- https://github.com/web-platform-dx/baseline-browser-mapping/commit/de733e2d8959559f7bb255d5927f3afcb6f31589
- https://github.com/web-platform-dx/baseline-browser-mapping
- https://github.com/web-platform-dx/baseline-browser-mapping/releases/tag/v2.11.0
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45819.json