CVE-2021-23364: Regular Expression Denial of Service (ReDoS)
Browserslist is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) during parsing of queries. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
Regular Expression Denial of Service (ReDoS) vulnerability was found in browserslist library. An attacker can use this vulnerability to parse a query which potentially can lead to service degradation.
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-23364?
CVE-2021-23364 is a vulnerability in the package browserslist from version 4.0.0 to 4.16.5 that allows for regular expression denial of service (ReDoS) attacks.
How severe is CVE-2021-23364?
CVE-2021-23364 has a severity score of 5.3 out of 10, which is considered medium.
How does CVE-2021-23364 affect Browserslist?
CVE-2021-23364 affects Browserslist versions 4.0.0 to 4.16.5, and can be exploited by sending specially-crafted requests to cause a denial of service.
How can I fix CVE-2021-23364?
To fix CVE-2021-23364, you should update Browserslist to version 4.16.6 or later.
Where can I find more information about CVE-2021-23364?
You can find more information about CVE-2021-23364 on the NIST National Vulnerability Database (NVD) website.