| Name | CVE-2021-23364 |
| Description | The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 987792 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| node-browserslist (PTS) | bullseye | 4.16.3+~cs5.4.72-3 | fixed |
| bookworm | 4.21.4+~cs6.1.17-2 | fixed |
| trixie | 4.25.0+~cs6.3.22-1 | fixed |
| forky, sid | 4.27.0+~cs8.11.53-2 | fixed |
The information below is based on the following data on fixed versions.
Notes
[buster] - node-browserslist <ignored> (Minor issue; risky backport with regression potential)
https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98
https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
https://github.com/browserslist/browserslist/pull/593