Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81075.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81075
Upstream
Published
2026-03-27T15:16:57Z
Modified
2026-08-31T05:26:07Z
Summary
CVE-2026-33750 affecting package js-jquery 3.5.0-4
Details

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., {1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to expand() to ensure a step value of 0 is not used.

References

Affected packages

Azure Linux:3 / js-jquery

Package

Name
js-jquery
Purl
pkg:rpm/azure-linux/js-jquery

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.5.0-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81075.json"