Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 31

Количество 31

nvd логотип

CVE-2026-69192

28 дней назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This i

EPSS: Низкий
debian логотип

CVE-2026-69192

28 дней назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

EPSS: Низкий
ubuntu логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-69152

25 дней назад

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

EPSS: Низкий
debian логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a c ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mwp4-54f8-5fhr

28 дней назад

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

EPSS: Низкий
rocky логотип

RLSA-2026:52841

20 дней назад

Important: nodejs-nodemon security update

EPSS: Низкий
github логотип

GHSA-rgw5-rvv9-x895

28 дней назад

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-52841

22 дня назад

ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-69192

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This i

0%
Низкий
28 дней назад
debian логотип
CVE-2026-69192

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

0%
Низкий
28 дней назад
ubuntu логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
redhat логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
nvd логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
msrc логотип
CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

1%
Низкий
25 дней назад
debian логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a c ...

CVSS3: 7.5
1%
Низкий
28 дней назад
github логотип
GHSA-mwp4-54f8-5fhr

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

0%
Низкий
28 дней назад
rocky логотип
RLSA-2026:52841

Important: nodejs-nodemon security update

1%
Низкий
20 дней назад
github логотип
GHSA-rgw5-rvv9-x895

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

CVSS3: 7.5
1%
Низкий
28 дней назад
oracle-oval логотип
ELSA-2026-52841

ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT)

1%
Низкий
22 дня назад

Уязвимостей на страницу