Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)
High
- Category
- Supply Chain
- Confidence
- 88% confidence
- Finding
- browserslist 4.28.1 appears in the dependency tree and the listed advisories include crash/prototype write and unbounded memory growth from untrusted stats or query input. Even though this is primarily build tooling, projects that ingest user- or repo-supplied browserslist data in CI, plugins, or automated services could suffer denial of service or unsafe object mutation.
