Allocation of Resources Without Limits or Throttling in browserslist - CVE-2026-73089
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `--` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
How to mitigate CVE-2026-73089
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - update to 16.2.0.3