Vulnerabilities in juliangruber
7 resultsVexday analysis
O fornecedor juliangruber apresenta 6 vulnerabilidades catalogadas, com 3 publicadas nos últimos 90 dias, indicando atividade de descoberta recente. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há críticas, reduzindo a urgência imediata. A fraqueza dominante (CWE-400: Uncontrolled Resource Consumption) sugere problemas de negação de serviço, tipicamente de menor gravidade mas relevante para a estabilidade operacional.
CVE-2021-41117HIGHInsecure random number generationEPSS 3.1%CVE-2025-5889LOWjuliangruber brace-expansion index.js expand redosEPSS 0.5%CVE-2026-33750MEDIUMbrace-expansion: Zero-step sequence causes process hang and memory exhaustionEPSS 0.4%CVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationEPSS 0.4%CVE-2026-13149HIGHbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number oEPSS 0.3%CVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crashEPSS 0.3%CVE-2026-45149MEDIUMbrace-expansion: Large numeric range defeats documented `max` DoS protectionEPSS 0.3%