Количество 24
Количество 24
GHSA-7h2j-956f-4vf2
@isaacs/brace-expansion has Uncontrolled Resource Consumption
CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.
CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.
CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.
CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ...
openSUSE-SU-2026:20261-1
Security update for openQA, os-autoinst, openQA-devel-container
BDU:2026-01718
Уязвимость библиотеки juliangruber/brace-expansion программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:20504-1
Security update for cockpit
openSUSE-SU-2026:20503-1
Security update for cockpit-machines
openSUSE-SU-2026:20502-1
Security update for cockpit-podman
openSUSE-SU-2026:20239-1
Security update for golang-github-prometheus-prometheus
SUSE-SU-2026:1008-1
Security update for Prometheus
openSUSE-SU-2026:21399-1
Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions
RLSA-2026:7302
Important: nodejs:22 security update
RLSA-2026:7123
Important: nodejs:22 security update
RLSA-2026:7080
Important: nodejs22 security update
ELSA-2026-7302
ELSA-2026-7302: nodejs:22 security update (IMPORTANT)
ELSA-2026-7123
ELSA-2026-7123: nodejs:22 security update (IMPORTANT)
ELSA-2026-7080
ELSA-2026-7080: nodejs22 security update (IMPORTANT)
SUSE-SU-2026:1013-1
Security update 5.0.7 for Multi-Linux Manager Client Tools
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7h2j-956f-4vf2 @isaacs/brace-expansion has Uncontrolled Resource Consumption | 0% Низкий | 6 месяцев назад | ||
CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1. | 0% Низкий | 6 месяцев назад | ||
CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1. | 0% Низкий | 6 месяцев назад | ||
CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ... | 0% Низкий | 6 месяцев назад | ||
openSUSE-SU-2026:20261-1 Security update for openQA, os-autoinst, openQA-devel-container | 0% Низкий | 5 месяцев назад | ||
BDU:2026-01718 Уязвимость библиотеки juliangruber/brace-expansion программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.6 | 0% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:20504-1 Security update for cockpit | 4 месяца назад | |||
openSUSE-SU-2026:20503-1 Security update for cockpit-machines | 4 месяца назад | |||
openSUSE-SU-2026:20502-1 Security update for cockpit-podman | 4 месяца назад | |||
openSUSE-SU-2026:20239-1 Security update for golang-github-prometheus-prometheus | 5 месяцев назад | |||
SUSE-SU-2026:1008-1 Security update for Prometheus | 4 месяца назад | |||
openSUSE-SU-2026:21399-1 Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions | 10 дней назад | |||
RLSA-2026:7302 Important: nodejs:22 security update | 4 месяца назад | |||
RLSA-2026:7123 Important: nodejs:22 security update | 4 месяца назад | |||
RLSA-2026:7080 Important: nodejs22 security update | 4 месяца назад | |||
ELSA-2026-7302 ELSA-2026-7302: nodejs:22 security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-7123 ELSA-2026-7123: nodejs:22 security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-7080 ELSA-2026-7080: nodejs22 security update (IMPORTANT) | 4 месяца назад | |||
SUSE-SU-2026:1013-1 Security update 5.0.7 for Multi-Linux Manager Client Tools | 4 месяца назад |
Уязвимостей на страницу