Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. baseline-browser-mapping
  4. ›
  5. CVE-2026-45819

CVE-2026-45819: baseline-browser-mapping process termination on invalid input causes denial of service

August 13, 2026 (updated September 8, 2026)

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

References

  • github.com/advisories/GHSA-w5vr-8v7q-w6rv
  • github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts
  • github.com/web-platform-dx/baseline-browser-mapping/commit/de733e2d8959559f7bb255d5927f3afcb6f31589
  • github.com/web-platform-dx/baseline-browser-mapping/pull/137
  • github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes
  • github.com/web-platform-dx/baseline-browser-mapping/releases/tag/v2.11.0
  • nvd.nist.gov/vuln/detail/CVE-2026-45819
  • www.npmjs.com/package/baseline-browser-mapping

Code Behaviors & Features

Detect and mitigate CVE-2026-45819 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.0.0 before 2.11.0

Fixed versions

  • 2.11.0

Solution

Upgrade to version 2.11.0 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-705: Incorrect Control Flow Scoping

Source file

npm/baseline-browser-mapping/CVE-2026-45819.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:19:51 +0000.