Описание
ELSA-2026-48032: nodejs-nodemon security update (IMPORTANT)
[3.1.14-2]
- Regenerete sources.
[3.1.14-1]
- Update to version 3.1.14
[3.0.3-7]
- revert of ce0df1a
[3.0.3-6]
- deps: revert letting nodemon work with any node
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
nodejs-nodemon
3.1.14-2.el10_2
Oracle Linux x86_64
nodejs-nodemon
3.1.14-2.el10_2
Связанные CVE
Связанные уязвимости
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
brace-expansion through 5.0.6 is vulnerable to denial of service. The ...