CVE-2026-73088Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-08-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-11: 1Mentions · 2026-09-02: 1Mentions · 2026-09-11: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-09-02: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-11: 108-1109-0209-11
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Akshara Hegde - oss/acc@akshara_dev
    Patch

    django-jet-3-calm 5.5.2 is out 🔒 security patch: browserslist → 4.28.9 (CVE-2026-73088) and decode-uri-component pinned to 0.5.0 (ReDoS, CVE-2026-45822) drop-in upgrade, no breaking changes

    Post summary

    The tweet announces a release of django‑jet‑3‑calm 5.5.2 that includes security patches for CVE‑2026‑73088 and CVE‑2026‑45822 via updated dependencies, with no active exploitation or PoC disclosed.

    10020461
    644 followersView on X
  • Thierry Bijou@thierrybijou
    Patch

    DID YOU KNOW? n8n 1.123.76 bumps browserslist to 4.28.7, fixing CVE-2026-73088 and CVE-2026-73089. Update your n8n instance to close this security gap. https://github.com/n8n-io/n8n/releases/tag/n8n%401.123.76

    Post summary

    n8n version 1.123.76 includes a patch that addresses CVE-2026-73088 and CVE-2026-73089; users are advised to update to mitigate the vulnerability.

    0000074
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-73088 Browserslist 4.28.7 Fixes Prototype Pollution via Untrusted Stats Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73088

    Post summary

    The text announces that version 4.28.7 of Browserslist resolves the prototype‑pollution vulnerability (CVE‑2026‑73088) caused by untrusted stats data, providing a patch.

    00000106
    4.1K followersView on X

Explore more