VDB
Sign up
MEDIUM5.3

GHSA-w8qv-6jwh-64r5

Regular Expression Denial of Service in browserslist

Quick fix

GHSA-w8qv-6jwh-64r5 — browserslist: upgrade to the fixed version with the command below.

npm install browserslist@4.16.5

Details

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/browserslist
Introduced in: 4.0.0Fixed in: 4.16.5
Fixnpm install browserslist@4.16.5

References