CVE-2021-23364 PUBLISHED

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

EPSS 0.33% · 56.0th percentile

Risk Scores

EPSS Score
0.33%
56.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSnode-browserslist0, 2.11.3-1build4
Ubuntu:18.04:LTSnode-browserslist2.11.3-1build3, 2.11.3-1build4, 2.11.3-1
Ubuntu:22.04:LTSnode-browserslist4.19.1+repack+~cs5.1.2-2, 4.19.3+~cs5.1.3-1, 0

Timeline

References

Open in Interactive Console →