Medium severity5.3NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-23364
CVE-2021-23364
Description
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
browserslistnpm | >= 4.0.0, < 4.16.5 | 4.16.5 |
Affected products
9- cpe:2.3:a:browserslist_project:browserslist:*:*:*:*:*:node.js:*:*Range: >=4.0.0,<4.16.5
- osv-coords7 versionspkg:apk/chainguard/arangodb-3.11pkg:apk/chainguard/arangodb-3.12pkg:apk/chainguard/py3.10-captumpkg:apk/chainguard/py3.11-captumpkg:apk/chainguard/py3.12-captumpkg:apk/chainguard/py3.13-captumpkg:npm/browserslist
< 3.11.14.5-r15+ 6 more
- (no CPE)range: < 3.11.14.5-r15
- (no CPE)range: < 3.12.9.4-r28
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: >= 4.0.0, < 4.16.5
Patches
Vulnerability mechanics
References
7- github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1277182nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-w8qv-6jwh-64r5ghsaADVISORY
- github.com/browserslist/browserslist/pull/593nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23364ghsaADVISORY
- github.com/browserslist/browserslist/blob/e82f32d1d4100d6bc79ea0b6b6a2d281a561e33c/index.js%23L472-L474nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.