CVE-2026-73089

Red Hat Security Advisory: RHOAI 2.25.11 - Red Hat OpenShift AI

Beschreibung

Browserslist ist ein Konfigurationstool zum Teilen von Zielbrowsern und Node.js-Versionen zwischen Front-End-Werkzeugen. Vor Version 4.28.7 speichert index.js jedes einzelne `(queries, context)`-Ergebnis im Cache und jeden parseQueries() AST in parseCache ohne Größenbegrenzung, TTL oder Eviction, was es einem Angreifer ermöglicht, der die wiederholten browserslist()-Abfragewerte beeinflussen kann, einschließlich gültiger seit `<jahr>-<monat>-<tag>`-Abfragen, das von dem Aufrufer kontrollierte BROWSERSLIST_DISABLE_CACHE-Minderungsmaß zu umgehen und eine lineare Speicherzuwachs gefolgt von einem Prozessabsturz durch Speichermangel zu verursachen. Dieses Problem wird in Version 4.28.7 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: cna-v3
29.3 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 07:57 UTC
CWE-770

Weakness-Klassen (CWE)

  • CWE-770Base

    Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. New CVE Received2026-08-11 17:19 UTC· security-advisories@github.com
    • Affected: browserslist
    • Description: Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `<year>-<month>-<day>` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    • CWE: CWE-770

Betroffene Betriebssysteme

  • linux

    ubuntu / ffmpegbionic

  • linux

    ubuntu / ffmpegfocal

  • linux

    ubuntu / ffmpegjammy

  • linux

    ubuntu / ffmpegnoble

  • linux

    ubuntu / ffmpegxenial

  • linux

    ubuntu / nettynoble

  • linux

    ubuntu / pyasn1jammy

  • linux

    ubuntu / pyasn1noble

  • linux

    ubuntu / pyasn1resolute

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    opennlp2.5.9

  • apache

    opennlp

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • beaugunderson

    ip-address10.1.1

  • bitnami

    golang1.25.0

  • bitnami

    golang1.26.0-0

  • bitnami

    thrift0.19.0

  • bitnami

    thrift

  • codehaus-plexus

    plexus-utils4.0.0 – 4.0.3

  • codehaus-plexus

    plexus-utils3.6.1

  • FasterXML

    Jackson2.18.6

  • FasterXML

    Jackson2.21.1

  • FasterXML

    Jackson3.1.0

  • follow-redirects_project

    follow-redirects1.16.0

Quellen & Referenzen

Verknüpfte CVEs

92 weitere CVEs anzeigen
IDCVE-2026-73089