MEDIUMnpm →
brace-expansion Regular Expression Denial of Service vulnerability
brace-expansion Regular Expression Denial of Service vulnerability
Affected packages
- brace-expansion
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2025-5889
- https://github.com/juliangruber/brace-expansion/pull/65/commits/a5b98a4f30d7813266b221435e1eaaf25a1b0ac5
- https://github.com/juliangruber/brace-expansion/commit/0b6a9781e18e9d2769bb2931f4856d1360243ed2
- https://github.com/juliangruber/brace-expansion/commit/15f9b3c75ebf5988198241fecaebdc45eff28a9f
- https://github.com/juliangruber/brace-expansion/commit/36603d5f3599a37af9e85eda30acd7d28599c36e
- https://github.com/juliangruber/brace-expansion/commit/c3c73c8b088defc70851843be88ccc3af08e7217
- https://gist.github.com/mmmsssttt404/37a40ce7d6e5ca604858fe30814d9466
- https://github.com/juliangruber/brace-expansion
- https://vuldb.com/?ctiid.311660
- https://vuldb.com/?id.311660
- https://vuldb.com/?submit.585717
Structured record: https://osv.dev/vulnerability/GHSA-v6h2-p8h4-qcjw
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta