ZeroHour

CVE-2021-23364

PoC ×2
CVSS 3.1
5.3 medium
EPSS
2%p83
Published
()
Modified
Description

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

Vendors
browserslist project
Products
browserslist
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.