CVE-2026-73089 is a high-severity (CVSS 3.1 base 7.5) unbounded-memory-growth vulnerability in Browserslist, published alongside CVE-2026-73088 and fixed in the same release.
What the vulnerability does
Per the GitHub Security Advisory (GHSA-c83g-rgw3-j3cx), Browserslist caches every distinct (queries, context) result it computes, forever — no size cap, TTL, or eviction, and browserslist.clearCaches() doesn’t reset this particular cache (it only clears an unrelated filesystem cache). Some Browserslist query forms make this worse: the since <year>-<month>-<day> query accepts essentially any digit combination without validating the date, giving an attacker who can influence the query string an effectively unbounded space of distinct, cheap-to-generate cache keys, each of which retains a result close to Browserslist’s full ~8.5 KB browser list.
The GitHub Advisory reports a measured ~150x memory amplification: 20,000 distinct since-date queries (roughly 330 KB of input) retained over 50 MB of heap permanently, growing linearly with no observed cap through 40,000 queries.
Fix and affected versions
Fixed in Browserslist 4.28.7. The fix replaces the unbounded plain-object caches with a bounded Map that evicts the oldest entry once a fixed maximum entry count is reached.
Why this matters
This is a volumetric attack rather than a single-request crash: exploitation requires sustained traffic over time, not one malicious payload, which is why the GitHub Advisory scores it in the same range as CVE-2026-73088 but characterizes it differently. Any long-running server or daemon that calls Browserslist with a query value influenced, even partially, by external input — rather than a fixed, developer-controlled query — is the realistic exposure case; a typical build-time-only use of Browserslist (the far more common usage pattern) isn’t affected in practice, since the process exits before the cache can grow meaningfully.
Frequently Asked Questions
What is CVE-2026-73089? A high-severity (CVSS 7.5) unbounded-memory-growth vulnerability in Browserslist, where an unbounded, never-evicted result cache can be filled with attacker-influenced distinct queries until the process runs out of memory.
Which version fixes CVE-2026-73089? Browserslist 4.28.7 and later, same as CVE-2026-73088.
Is CVE-2026-73089 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the GitHub Advisory Database and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.