Количество 14
Количество 14
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-69152
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a c ...
RLSA-2026:52841
Important: nodejs-nodemon security update
GHSA-rgw5-rvv9-x895
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
ELSA-2026-52841
ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT)
RLSA-2026:55541
Important: nodejs22 security update
ELSA-2026-55541
ELSA-2026-55541: nodejs22 security update (IMPORTANT)
ELSA-2026-55601
ELSA-2026-55601: nodejs:22 security update (IMPORTANT)
ELSA-2026-54530
ELSA-2026-54530: nodejs:22 security update (IMPORTANT)
ELSA-2026-55603
ELSA-2026-55603: nodejs:24 security update (IMPORTANT)
ELSA-2026-54371
ELSA-2026-54371: nodejs:24 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. | CVSS3: 7.5 | 0% Низкий | 28 дней назад | |
CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. | CVSS3: 7.5 | 0% Низкий | 28 дней назад | |
CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. | CVSS3: 7.5 | 0% Низкий | 28 дней назад | |
CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation | 0% Низкий | 25 дней назад | ||
CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a c ... | CVSS3: 7.5 | 0% Низкий | 28 дней назад | |
RLSA-2026:52841 Important: nodejs-nodemon security update | 0% Низкий | 20 дней назад | ||
GHSA-rgw5-rvv9-x895 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation | CVSS3: 7.5 | 0% Низкий | 28 дней назад | |
ELSA-2026-52841 ELSA-2026-52841: nodejs-nodemon security update (IMPORTANT) | 0% Низкий | 22 дня назад | ||
RLSA-2026:55541 Important: nodejs22 security update | 13 дней назад | |||
ELSA-2026-55541 ELSA-2026-55541: nodejs22 security update (IMPORTANT) | 15 дней назад | |||
ELSA-2026-55601 ELSA-2026-55601: nodejs:22 security update (IMPORTANT) | 14 дней назад | |||
ELSA-2026-54530 ELSA-2026-54530: nodejs:22 security update (IMPORTANT) | 18 дней назад | |||
ELSA-2026-55603 ELSA-2026-55603: nodejs:24 security update (IMPORTANT) | 14 дней назад | |||
ELSA-2026-54371 ELSA-2026-54371: nodejs:24 security update (IMPORTANT) | 18 дней назад |
Уязвимостей на страницу