Incorrect Control Flow Scoping in baseline-browser-mapping - CVE-2026-45819
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to baseline-browser-mapping calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Maximo Application Suite - Monitor Component
How to mitigate CVE-2026-45819
Maximo Application Suite - Monitor Component - addressed in versions 9.0.25, 9.1.15, 9.2.4
External References
- https://github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts#L142
- https://github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes#diff-7ae45ad102eab3b6d7e7896acd08c427a9b25b346470d7bc6507b6481575d519
- https://www.npmjs.com/package/baseline-browser-mapping