CVE-2026-45819: baseline-browser-mapping process termination on invalid input causes denial of service
(updated )
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
References
- github.com/advisories/GHSA-w5vr-8v7q-w6rv
- github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts
- github.com/web-platform-dx/baseline-browser-mapping/commit/de733e2d8959559f7bb255d5927f3afcb6f31589
- github.com/web-platform-dx/baseline-browser-mapping/pull/137
- github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes
- github.com/web-platform-dx/baseline-browser-mapping/releases/tag/v2.11.0
- nvd.nist.gov/vuln/detail/CVE-2026-45819
- www.npmjs.com/package/baseline-browser-mapping
Code Behaviors & Features
Detect and mitigate CVE-2026-45819 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →