Browserslist Project maintains a JavaScript library used in build toolchains and frontend development environments to query and filter browser compatibility data; despite its niche direct exposure, the library's position in the dependency chain of development tools gives it broad downstream reach. The observed vulnerability signal centers on inefficient regular expression complexity, a parsing-oriented weakness class that can degrade performance or consume excessive resources when handling certain inputs. Current vulnerability counts, severity, and any in-the-wild activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Browserslist Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23364MEDIUM The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. | Apr 28, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Browserslist Project.
Media articles that mention a CVE ID that affects a product developed by Browserslist Project — matched by CVE ID, not by vendor name.