Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q2hr-2g5m-vwhr
  • npm/brace-expansion
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service 6 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-qhr7-859c-m2p7
  • npm/brace-expansion
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-6j4f-fj2g-mc7p
  • npm/brace-expansion
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-rgw5-rvv9-x895
  • npm/brace-expansion
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation 03 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-mh99-v99m-4gvg
  • npm/brace-expansion
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-3jxr-9vmj-r5cp
  • npm/brace-expansion
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups 20 Jul
  • Fix available
  • Severity - 7.7 (High)
GHSA-jxxr-4gwj-5jf2
  • npm/brace-expansion
brace-expansion: Large numeric range defeats documented `max` DoS protection 18 May
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-f886-m6hf-6m8v
  • npm/brace-expansion
brace-expansion: Zero-step sequence causes process hang and memory exhaustion 26 Mar
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-v6h2-p8h4-qcjw
  • npm/brace-expansion
brace-expansion Regular Expression Denial of Service vulnerability 09 Jun 2025
  • Fix available
  • Severity - 1.3 (Low)
GHSA-832h-xg76-4gv6
  • npm/brace-expansion
ReDoS in brace-expansion 29 Jan 2018
  • Fix available
  • Severity - 7.5 (High)