CVE-2026-45819
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
- EPSS probability
- 0.37%
- CWE
- CWE-705, CWE-755
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- web-platform-dx baseline-browser-mapping
Weakness type
Related vulnerabilities
- CVE-2026-55537 — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-3449 — Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow...
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2025-53856 — TMM vulnerability
- CVE-2025-9848 — ScriptAndTools Real Estate Management System userlist.php redirect