CVE-2026-73088

Aliases:DEBIAN-CVE-2026-73088UBUNTU-CVE-2026-73088openSUSE-SU-2026:11540-1openSUSE-SU-2026:11535-1GHSA-73wf-gq98-2v4gCGA-57m8-f4cq-q65rCGA-5r4x-7v4w-9q7jCGA-69rq-j35w-33h7CGA-78f4-cv92-f2j4CGA-98w4-qxc3-hv9pCGA-fcf6-44fq-48g3CGA-fr3q-4pjc-jrv6CGA-g423-327m-rx27CGA-gjg6-gf7h-hg33CGA-mwr2-pjpj-p8r4CGA-pmpj-74p9-9qpxCGA-27xr-7qx2-p8h4CGA-2g4c-82ph-9hrpCGA-2gh4-rw9p-w7pwCGA-2ppw-xhf3-22xrCGA-2q8x-w3jj-f7mqCGA-2rc4-frvc-4f94CGA-2xq5-vhgq-m69rCGA-35rf-ppcw-cc9xCGA-3fmm-94h8-59xfCGA-3q8v-8rrq-w6jjCGA-3qrx-x934-9j9wCGA-3x78-559x-9jmmCGA-45f6-qjvv-ww7pCGA-4996-ghvx-755qCGA-49c8-pqj9-ggm7CGA-4ggh-82r7-f8vpCGA-4pv6-99mx-3h3hCGA-4w8f-jjr5-mcmmCGA-5357-5xj8-v673CGA-5468-hchh-3qvhCGA-569g-c68q-fpfvCGA-58qh-fwrm-rxwmCGA-597m-rg26-x2mxCGA-59q4-2ww3-x8rwCGA-5f43-6wm8-vg8xCGA-5jjx-58m5-xj82CGA-69g7-4grw-2vhrCGA-69h4-59m3-g28wCGA-6j6g-389g-3fh4CGA-7fgc-fv9g-4w5rCGA-7mf9-vxrj-2gc3CGA-7vvf-xfg6-4q63CGA-7xmq-9qq5-fwhwCGA-867w-3624-2j86CGA-869f-38fq-qg98CGA-9hrg-3r52-8mg8CGA-9q6m-949j-78c6CGA-9v3r-rv55-cmf9CGA-c4wx-24x8-mf5mCGA-c942-4jph-g54xCGA-chw2-xj4f-rq84CGA-cw5j-prmg-267hCGA-f25p-m77q-j5wcCGA-f6h3-m3pw-9whmCGA-f8w9-fqg3-56h7CGA-f96x-7xcm-j4j3CGA-f9gw-f5jq-7prjCGA-fg7m-pmjf-75xfCGA-fg7x-pjxw-6jjhCGA-fw4c-f4xr-phqrCGA-g2gj-2qw5-rf57CGA-g94v-r62g-v7hxCGA-gmm8-qmrw-h2grCGA-gr3v-mqh4-629pCGA-h493-p497-vj7hCGA-hpx9-8r85-jcqxCGA-hwh4-x5jc-4cf4CGA-j5mw-7p6g-448cCGA-j8vj-8f9p-7q8fCGA-jghg-fx62-m77jCGA-jjmr-2732-55mgCGA-m6mv-8jgp-9jr2CGA-mg8g-53qw-qc36CGA-mp83-gg6g-hm4mCGA-mq64-qm5r-rxhwCGA-mvhx-f2m7-x8jwCGA-mwqv-2q3x-7wqqCGA-p6vf-qjfx-qwwwCGA-p92w-2g5m-fpcjCGA-pcr7-95w9-67p9CGA-pp2w-jcw8-vrrvCGA-pp4g-526x-hpc7CGA-prjg-6h3j-q47xCGA-pw3q-mwwf-f3pjCGA-q3v7-3mcw-42pxCGA-q4p9-jpcc-cjhxCGA-qggj-fxp7-pgcjCGA-qqx3-h72j-h7fjCGA-qvvh-m439-mcr3CGA-r49j-66qm-5mw6CGA-r4f7-x236-8wx4CGA-r5xc-9h5m-p66cCGA-r6v8-8cq9-5897CGA-r7r9-xhq8-69g6CGA-r8r8-vqfw-hjc4CGA-rr5g-rxrv-7v95CGA-rv5q-82rg-2jvrCGA-v8pw-wc5f-vccfCGA-vcrh-436f-79cwCGA-vj5w-rx4j-8m3vCGA-vmxm-55cq-732rCGA-vvmc-ch2w-6rpfCGA-vvpf-j47m-25hjCGA-vwp8-583p-v5fcCGA-w5hp-8r68-pg54CGA-w99m-f944-cmcqCGA-w9qf-24vh-24jwCGA-wmg6-xxmf-996vCGA-wv67-cq6h-r5p7CGA-x36j-p2w2-vxjwCGA-x8hr-v86r-j8cvCGA-xr7p-92f4-wj6rCGA-fq5r-w3p4-9hh3CGA-gj5w-9f97-8v8wCGA-qh2h-hpgq-qwf6CGA-xm5f-v326-rw2hCGA-pxrg-v6q3-fwv8CGA-vqhx-gc65-68q5CGA-3rqm-8cmv-xphqCGA-h8g3-8j3r-p3rcCGA-rfpw-fvj3-pp4xCGA-xmpq-m78m-562mCGA-3cm7-4f7w-472gCGA-55j8-jfj4-x9xpCGA-6wx6-79gq-7c2gCGA-r2c9-g986-gw8gCGA-rpj5-284g-42w2
Advisory lineage Upstream: 0 Downstream: 4
Awaiting Analysis
Published: 11 Aug 2026, 17:00
Last modified:13 Aug 2026, 14:50

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.44% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Aug 2026, 17:00
Published
Vulnerability first disclosed
13 Aug 2026, 14:50
Last Modified
Vulnerability information updated

Description

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.44% Percentile: 38%

Techniques & Countermeasures

  • CWE-248Uncaught Exception

    An exception is thrown from a function, but it is not caught.

  • CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.5-r15

  • chainguardarangodb-3.12

    < 3.12.9.4-r28

  • chainguardargo-workflows-ui-4.0

    < 4.0.11-r0

  • chainguardauthentik-2025.12

    < 2025.12.6-r13

  • chainguardauthentik-2026.5

    < 2026.5.6-r16

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r15

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r40

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    all | < 3.225.7-r4

  • chainguardlangfuse-4-worker

    < 4.27.0-r2

  • chainguardlangfuse-fips-3-worker

    < 3.225.5-r1

  • chainguardlangfuse-fips-4-worker

    < 4.26.0-r2

  • chainguardnextcloud-server-32

    < 32.0.14-r2

  • chainguardnextcloud-server-34

    < 34.0.3-r4

  • chainguardtensorflow-gpu-jupyter

    all | < 2.21.0-r9

  • chainguardts-patch

    < 4.0.1-r44

  • chainguardvitess-22

    < 22.0.4-r22

  • chainguardvitess-23

    < 23.0.6-r3

  • chainguardvitess-24

    < 24.0.3-r1

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • chainguardwazuh-dashboard-dashboards-reporting

    < 4.14.7-r13

  • chainguardwazuh-dashboard-dashboards-reporting-fips

    < 4.14.7-r14

  • wolfiargo-workflows-ui-4.0

    < 4.0.11-r0

  • wolfijupyter-base-notebook

    all

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r40

  • wolfilangfuse-3-compat

    < 3.225.7-r6

Showing first 50 affected entries in server-rendered view.

References (10)