Количество 21
Количество 21
GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The ...
openSUSE-SU-2026:21312-1
Security update for python-pytest-html
RLSA-2026:48032
Important: nodejs-nodemon security update
ELSA-2026-48032
ELSA-2026-48032: nodejs-nodemon security update (IMPORTANT)
RLSA-2026:48034
Important: nodejs24 security update
RLSA-2026:48033
Important: nodejs22 security update
RLSA-2026:47060
Important: nodejs:24 security update
RLSA-2026:47059
Important: nodejs:22 security update
RLSA-2026:47058
Important: nodejs:22 security update
RLSA-2026:47057
Important: nodejs:24 security update
ELSA-2026-48034
ELSA-2026-48034: nodejs24 security update (IMPORTANT)
ELSA-2026-48033
ELSA-2026-48033: nodejs22 security update (IMPORTANT)
ELSA-2026-47060
ELSA-2026-47060: nodejs:24 security update (IMPORTANT)
ELSA-2026-47059
ELSA-2026-47059: nodejs:22 security update (IMPORTANT)
ELSA-2026-47058
ELSA-2026-47058: nodejs:22 security update (IMPORTANT)
ELSA-2026-47057
ELSA-2026-47057: nodejs:24 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | 0% Низкий | 3 месяца назад | ||
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | 0% Низкий | 3 месяца назад | ||
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The ... | 0% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:21312-1 Security update for python-pytest-html | 0% Низкий | 3 месяца назад | ||
RLSA-2026:48032 Important: nodejs-nodemon security update | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-48032 ELSA-2026-48032: nodejs-nodemon security update (IMPORTANT) | 0% Низкий | около 2 месяцев назад | ||
RLSA-2026:48034 Important: nodejs24 security update | около 2 месяцев назад | |||
RLSA-2026:48033 Important: nodejs22 security update | около 2 месяцев назад | |||
RLSA-2026:47060 Important: nodejs:24 security update | около 2 месяцев назад | |||
RLSA-2026:47059 Important: nodejs:22 security update | около 2 месяцев назад | |||
RLSA-2026:47058 Important: nodejs:22 security update | около 2 месяцев назад | |||
RLSA-2026:47057 Important: nodejs:24 security update | около 2 месяцев назад | |||
ELSA-2026-48034 ELSA-2026-48034: nodejs24 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-48033 ELSA-2026-48033: nodejs22 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47060 ELSA-2026-47060: nodejs:24 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47059 ELSA-2026-47059: nodejs:22 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47058 ELSA-2026-47058: nodejs:22 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47057 ELSA-2026-47057: nodejs:24 security update (IMPORTANT) | около 2 месяцев назад |
Уязвимостей на страницу