Количество 9
Количество 9
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The ...
openSUSE-SU-2026:21312-1
Security update for python-pytest-html
GHSA-3jxr-9vmj-r5cp
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
RLSA-2026:47060
Important: nodejs:24 security update
RLSA-2026:47059
Important: nodejs:22 security update
openSUSE-SU-2026:21448-1
Security update for agama-web-ui
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. | 0% Низкий | около 1 месяца назад | ||
CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The ... | 0% Низкий | около 1 месяца назад | ||
openSUSE-SU-2026:21312-1 Security update for python-pytest-html | 0% Низкий | 23 дня назад | ||
GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups | CVSS3: 5.3 | 0% Низкий | 12 дней назад | |
RLSA-2026:47060 Important: nodejs:24 security update | 5 дней назад | |||
RLSA-2026:47059 Important: nodejs:22 security update | 4 дня назад | |||
openSUSE-SU-2026:21448-1 Security update for agama-web-ui | 6 дней назад |
Уязвимостей на страницу