{"id":"CVE-2026-73088","title":"Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools","summary":"Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist()…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-248","CWE-1321","CWE-915"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["cryostat 4","migration_toolkit_for_containers","node_healthcheck_operator","openshift_lightspeed","openshift_pipelines","ansible_automation_platform 2","build_of_apache_camel_hawtio 4","build_of_podman_desktop","ceph_storage 9","connectivity_link 1","edge_manager 1","enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform 8","openshift_ai_rhoai","openshift_data_foundation 4","openshift_dev_spaces","satellite 6","single_sign_on 7","trusted_artifact_signer","secrets_management_console_for_red_hat_openshift","ansible_automation_platform 2.1","ansible_automation_platform 2.2","discovery 2","hardened_images","openshift_ai 2.25","openshift_container_platform 4.21","openshift_container_platform 4.22","openshift_service_mesh 3.0","openshift_service_mesh 3.1","openshift_service_mesh 3.2","openshift_service_mesh 3.3","openshift_service_mesh 3.4","quay 3.9","satellite 6.18","satellite 6.19"],"patched":["ansible_automation_platform 2.1","ansible_automation_platform 2.2","discovery 2","hardened_images","openshift_ai 2.25","openshift_container_platform 4.21","openshift_container_platform 4.22","openshift_service_mesh 3.0","openshift_service_mesh 3.1","openshift_service_mesh 3.2","openshift_service_mesh 3.3","openshift_service_mesh 3.4","quay 3.9","satellite 6.18","satellite 6.19"],"published":"2026-08-11","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:44:04.357","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73088","references":[{"url":"https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51","label":"security-advisories@github.com"},{"url":"https://github.com/browserslist/browserslist/releases/tag/4.28.7","label":"security-advisories@github.com"},{"url":"https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g","label":"security-advisories@github.com"},{"url":"https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73088.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-73088"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514177"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73088"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73088"},{"url":"https://access.redhat.com/errata/RHSA-2026:56338"},{"url":"https://access.redhat.com/errata/RHSA-2026:56357"},{"url":"https://access.redhat.com/errata/RHSA-2026:54760"},{"url":"https://access.redhat.com/errata/RHSA-2026:54518"},{"url":"https://access.redhat.com/errata/RHSA-2026:54517"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60478"},{"url":"https://access.redhat.com/errata/RHSA-2026:60442"},{"url":"https://access.redhat.com/errata/RHSA-2026:59548"},{"url":"https://access.redhat.com/errata/RHSA-2026:59561"},{"url":"https://access.redhat.com/errata/RHSA-2026:59554"},{"url":"https://access.redhat.com/errata/RHSA-2026:59566"},{"url":"https://access.redhat.com/errata/RHSA-2026:59583"},{"url":"https://access.redhat.com/errata/RHSA-2026:65514"},{"url":"https://access.redhat.com/errata/RHSA-2026:63373"},{"url":"https://access.redhat.com/errata/RHSA-2026:63355"},{"url":"https://github.com/advisories/GHSA-73wf-gq98-2v4g"},{"url":"https://access.redhat.com/errata/RHSA-2026:66084"},{"url":"https://access.redhat.com/errata/RHSA-2026:66523"},{"url":"https://access.redhat.com/errata/RHSA-2026:68044"},{"url":"https://access.redhat.com/errata/RHSA-2026:68253"},{"url":"https://access.redhat.com/errata/RHSA-2026:68681"},{"url":"https://access.redhat.com/errata/RHSA-2026:68754"},{"url":"https://access.redhat.com/errata/RHSA-2026:68765"}],"tags":["nvd","csaf","vex","red-hat","ghsa","npm"],"epss":0.00439,"epssPercentile":0.37464,"aliases":["GHSA-73wf-gq98-2v4g"],"ecosystem":"npm","ingestedAt":"2026-09-01T17:29:54.655Z","slug":"CVE-2026-73088","body":"## Overview\n\nBrowserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73088)\n\nAffected packages:\n\n- `browserslist <= 4.28.6`\n\nPatched in:\n\n- `browserslist 4.28.7`\n\nSource: https://github.com/advisories/GHSA-73wf-gq98-2v4g\n\n## Vendor advisories\n\n- **RHSA-2026:56338** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56338)\n- **RHSA-2026:56357** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56357)\n- **RHSA-2026:54760** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54760)\n- **RHSA-2026:54518** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54518)\n- **RHSA-2026:54517** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54517)\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **RHSA-2026:60478** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60478)\n- **RHSA-2026:60442** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60442)\n- **RHSA-2026:59548** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.0 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59548)\n- **RHSA-2026:59561** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.1 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59561)\n- **RHSA-2026:59554** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.2 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59554)\n- **Red Hat VEX** · Important · affected: Node HealthCheck Operator, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat build of Apache Camel - HawtIO 4, Red Hat Build of Podman Desktop, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat JBoss Enterprise Application Platform 7, Secrets Management Console for Red Hat OpenShift, Node HealthCheck Operator, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73088.json)\n- **RHSA-2026:68044** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68044)\n- **RHSA-2026:68253** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68253)\n- **RHSA-2026:68681** · Red Hat · fixed in: Red Hat Migration Toolkit 1.8 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68681)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}