Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

github логотип

GHSA-rgw5-rvv9-x895

28 дней назад

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-69152

25 дней назад

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

EPSS: Низкий
debian логотип

CVE-2026-69152

28 дней назад

The brace-expansion library generates arbitrary strings containing a c ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:52841

20 дней назад

Important: nodejs-nodemon security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-52841

22 дня назад

ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:55541

13 дней назад

Important: nodejs22 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55541

15 дней назад

ELSA-2026-55541: nodejs22 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:58819

6 дней назад

Important: nodejs24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-58819

7 дней назад

ELSA-2026-58819: nodejs24 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:55601

6 дней назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:54530

6 дней назад

Important: nodejs:22 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55601

14 дней назад

ELSA-2026-55601: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54530

18 дней назад

ELSA-2026-54530: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:55603

6 дней назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:54371

6 дней назад

Important: nodejs:24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55603

14 дней назад

ELSA-2026-55603: nodejs:24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-54371

18 дней назад

ELSA-2026-54371: nodejs:24 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rgw5-rvv9-x895

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

CVSS3: 7.5
1%
Низкий
28 дней назад
ubuntu логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
redhat логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
nvd логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS3: 7.5
1%
Низкий
28 дней назад
msrc логотип
CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

1%
Низкий
25 дней назад
debian логотип
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a c ...

CVSS3: 7.5
1%
Низкий
28 дней назад
rocky логотип
RLSA-2026:52841

Important: nodejs-nodemon security update

1%
Низкий
20 дней назад
oracle-oval логотип
ELSA-2026-52841

ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT)

1%
Низкий
22 дня назад
rocky логотип
RLSA-2026:55541

Important: nodejs22 security update

13 дней назад
oracle-oval логотип
ELSA-2026-55541

ELSA-2026-55541: nodejs22 security update (IMPORTANT)

15 дней назад
rocky логотип
RLSA-2026:58819

Important: nodejs24 security update

6 дней назад
oracle-oval логотип
ELSA-2026-58819

ELSA-2026-58819: nodejs24 security update (IMPORTANT)

7 дней назад
rocky логотип
RLSA-2026:55601

Important: nodejs:22 security update

6 дней назад
rocky логотип
RLSA-2026:54530

Important: nodejs:22 security update

6 дней назад
oracle-oval логотип
ELSA-2026-55601

ELSA-2026-55601: nodejs:22 security update (IMPORTANT)

14 дней назад
oracle-oval логотип
ELSA-2026-54530

ELSA-2026-54530: nodejs:22 security update (IMPORTANT)

18 дней назад
rocky логотип
RLSA-2026:55603

Important: nodejs:24 security update

6 дней назад
rocky логотип
RLSA-2026:54371

Important: nodejs:24 security update

6 дней назад
oracle-oval логотип
ELSA-2026-55603

ELSA-2026-55603: nodejs:24 security update (IMPORTANT)

14 дней назад
oracle-oval логотип
ELSA-2026-54371

ELSA-2026-54371: nodejs:24 security update (IMPORTANT)

18 дней назад

Уязвимостей на страницу