Medium severity5.3NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-23364
CVE-2021-23364
Description
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
browserslistnpm | >= 4.0.0, < 4.16.5 | 4.16.5 |
Affected products
6- browserslist/browserslistdescription
- osv-coords5 versionspkg:apk/chainguard/py3.10-captumpkg:apk/chainguard/py3.11-captumpkg:apk/chainguard/py3.12-captumpkg:apk/chainguard/py3.13-captumpkg:npm/browserslist
< 0.9.0-r1+ 4 more
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: >= 4.0.0, < 4.16.5
Patches
Vulnerability mechanics
References
7- github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1277182nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-w8qv-6jwh-64r5ghsaADVISORY
- github.com/browserslist/browserslist/pull/593nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23364ghsaADVISORY
- github.com/browserslist/browserslist/blob/e82f32d1d4100d6bc79ea0b6b6a2d281a561e33c/index.js%23L472-L474nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.