Логотип exploitDog
bind:"GHSA-7h2j-956f-4vf2" OR bind:"CVE-2026-25547"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-7h2j-956f-4vf2" OR bind:"CVE-2026-25547"

Количество 8

Количество 8

github логотип

GHSA-7h2j-956f-4vf2

около 2 месяцев назад

@isaacs/brace-expansion has Uncontrolled Resource Consumption

EPSS: Низкий
ubuntu логотип

CVE-2026-25547

около 2 месяцев назад

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

EPSS: Низкий
redhat логотип

CVE-2026-25547

около 2 месяцев назад

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-25547

около 2 месяцев назад

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

EPSS: Низкий
debian логотип

CVE-2026-25547

около 2 месяцев назад

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ...

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20261-1

около 1 месяца назад

Security update for openQA, os-autoinst, openQA-devel-container

EPSS: Низкий
fstec логотип

BDU:2026-01718

около 2 месяцев назад

Уязвимость библиотеки juliangruber/brace-expansion программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20239-1

около 1 месяца назад

Security update for golang-github-prometheus-prometheus

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7h2j-956f-4vf2

@isaacs/brace-expansion has Uncontrolled Resource Consumption

0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-25547

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-25547

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-25547

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-25547

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ...

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20261-1

Security update for openQA, os-autoinst, openQA-devel-container

0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-01718

Уязвимость библиотеки juliangruber/brace-expansion программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20239-1

Security update for golang-github-prometheus-prometheus

около 1 месяца назад

Уязвимостей на страницу