CVE-2026-73089

Aliases:DEBIAN-CVE-2026-73089UBUNTU-CVE-2026-73089GHSA-c83g-rgw3-j3cxCGA-28gp-7g97-mqmxCGA-28xg-4rff-6pfpCGA-3jgf-vm85-46cmCGA-3mm7-j44m-9jjwCGA-5xp4-4c66-fg7hCGA-6c9h-5hpj-495jCGA-6m95-26qm-2wg8CGA-7cgw-f9m9-9p8wCGA-99cr-p48c-9r96CGA-9vp4-h9g9-c8cpCGA-c4vh-4qwj-274xCGA-g4x4-4mh5-4wf3CGA-jf5q-hphw-gpcfCGA-jjjx-mp8x-q338CGA-ph8g-qq9q-fcm9CGA-22v5-2g6v-pr6xCGA-232f-p7fh-m27pCGA-2586-6qp3-5298CGA-25pv-4wrg-2ph5CGA-25q3-wvff-3x83CGA-299j-cxvx-7cpmCGA-2c2w-fgw3-579mCGA-2c98-595m-q9jvCGA-2qgf-fj63-2w7xCGA-2rq7-mf88-m3v2CGA-2ww2-v739-ggv4CGA-38f7-7vfx-p22xCGA-3f2q-4v66-f6mhCGA-3f2x-grq2-36phCGA-3rvc-4hhw-7wp3CGA-3x38-prhj-hwrjCGA-4279-6w67-3xq6CGA-498j-6xpf-cq4rCGA-49pw-739c-6972CGA-4jhm-h3gx-9jfvCGA-4m9g-3p5m-rr93CGA-4mqq-849f-9xvfCGA-4rhp-fpj3-v689CGA-54r5-j468-g58qCGA-5575-cr4j-23hqCGA-5c7f-633w-fvc3CGA-5fw8-3475-8434CGA-5h9g-6rwf-cw78CGA-5jjh-hmc8-7m93CGA-5m4m-4j23-cgjxCGA-5w2x-mxm2-3fm5CGA-5whv-qv87-8hx2CGA-65f2-g5gc-2464CGA-6cjv-2jcp-rv9qCGA-794q-rgp2-7pj4CGA-7f4f-7hq6-v654CGA-7gxw-qhg7-3px3CGA-7pq4-p6q9-9w54CGA-7rqf-mh4m-xv47CGA-7rr3-2xxg-h7r9CGA-7vg7-jrq4-hrfpCGA-7vwp-2vmj-gv2pCGA-83jf-j656-gf4jCGA-8gq3-jq9w-c47mCGA-8mw4-v23g-3v7hCGA-9467-h6xg-4vp3CGA-9cx9-r9xc-2pwrCGA-c499-wp8h-7g2hCGA-c54r-53qg-rc4pCGA-c6r2-hh3j-xvxhCGA-crwg-rm5p-7jxvCGA-cx46-276h-4xhmCGA-f3q9-cqxc-jx2hCGA-f6vj-j955-948pCGA-f7m7-mvrj-vxmgCGA-f898-v96q-wghvCGA-f94r-wr98-xw84CGA-ffcr-53w6-27c4CGA-fm99-9556-qhqrCGA-fp2m-42ww-fqj9CGA-fq9w-gwp7-5ccqCGA-fqpr-3x6c-r8h9CGA-fr4x-73p8-8x62CGA-fw2p-6f48-gvrwCGA-g4gq-f8f5-3w38CGA-g9cg-qqc6-f284CGA-gc37-953r-62h2CGA-gcpj-x284-35mwCGA-gq2j-xgvm-fwpfCGA-h55h-7f56-767xCGA-j6v8-2cr4-8mvxCGA-m2vh-fmw8-p432CGA-m635-96gw-8xfgCGA-m8vh-8f3j-rfqmCGA-mf6c-prf7-6m2qCGA-mvh9-2g43-w9jfCGA-pc6r-x4mj-2p6pCGA-pfqj-32v6-r936CGA-pgw5-7wr5-whx4CGA-pwvg-m226-6g88CGA-q9m5-vgcr-7q6hCGA-qp8f-w695-h4h2CGA-qr3g-64w7-95fwCGA-r9gw-2pwj-h624CGA-rfr6-wfv9-w9w6CGA-rhw9-8g9f-7qr3CGA-rm4f-6898-h568CGA-vcww-3ffj-38w2CGA-vf5p-q2hf-r3wxCGA-vjgp-gfxw-698gCGA-vv5r-pv54-fcrfCGA-wmc7-8x7c-4rxgCGA-wv9m-43w6-3vwmCGA-ww3x-mjph-23rvCGA-x35x-c9v7-f4jxCGA-x5x4-42wx-3ch9CGA-xj8w-32hw-5pwcCGA-xpmg-xhj7-528wCGA-hc5m-rfhx-6pjrCGA-rf75-vjmr-fcvvCGA-73g3-7m37-h883CGA-9p58-p2c5-xhv5CGA-2j7q-8m96-f2r4CGA-729h-58fx-585gCGA-9fc9-x774-4fr5CGA-pr77-f4mx-c32qCGA-38p4-cwc6-8w6xCGA-5cm9-mm96-23fxCGA-5vcg-xxmg-c5w8CGA-86vp-mvmj-wrhpCGA-qrmp-q63m-w52m
Advisory lineage Upstream: 0 Downstream: 4
Awaiting Analysis
Published: 11 Aug 2026, 17:05
Last modified:13 Aug 2026, 14:07

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.47% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Aug 2026, 17:05
Published
Vulnerability first disclosed
13 Aug 2026, 14:07
Last Modified
Vulnerability information updated

Description

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.5-r15

  • chainguardarangodb-3.12

    < 3.12.9.4-r28

  • chainguardargo-workflows-ui-4.0

    < 4.0.11-r0

  • chainguardauthentik-2025.12

    < 2025.12.6-r13

  • chainguardauthentik-2026.5

    < 2026.5.6-r16

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r15

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r40

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    all | < 3.225.7-r4

  • chainguardlangfuse-4-worker

    < 4.27.0-r2

  • chainguardlangfuse-fips-3-worker

    < 3.225.5-r1

  • chainguardlangfuse-fips-4-worker

    < 4.26.0-r2

  • chainguardnextcloud-server-32

    < 32.0.14-r2

  • chainguardnextcloud-server-34

    < 34.0.3-r4

  • chainguardtensorflow-gpu-jupyter

    all | < 2.21.0-r9

  • chainguardts-patch

    < 4.0.1-r44

  • chainguardvitess-22

    < 22.0.4-r22

  • chainguardvitess-23

    < 23.0.6-r3

  • chainguardvitess-24

    < 24.0.3-r1

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • chainguardwazuh-dashboard-dashboards-reporting

    < 4.14.7-r13

  • chainguardwazuh-dashboard-dashboards-reporting-fips

    < 4.14.7-r14

  • wolfiargo-workflows-ui-4.0

    < 4.0.11-r0

  • wolfijupyter-base-notebook

    all

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r40

  • wolfilangfuse-3-compat

    < 3.225.7-r6

Showing first 50 affected entries in server-rendered view.

References (9)