Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 The brace-expansion library versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11 contain a vulnerability where deeply nested brace groups cause uncontrolled recursion in the expand_() function. This leads to native stack exhaustion and can terminate the Node.js process, resulting in a denial of service. The issue affects multiple expansion scenarios including comma members and single sets. The vulnerability is fixed in the specified versions. Join the discussion | CVE Database V5 | 09/28/2026, 20:57:09 UTC Added: 09/28/2026, 21:03:53 UTC |
0 CVE-2026-102277 is a medium severity vulnerability in the juliangruber brace-expansion library that causes uncontrolled resource consumption. The expand function in affected versions repeatedly rescans input patterns with many trailing closing braces, leading to quadratic CPU and memory usage. This results in a recoverable denial of service by blocking the Node.js event loop. The issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12. Join the discussion | CVE Database V5 | 09/28/2026, 20:54:46 UTC Added: 09/28/2026, 21:03:53 UTC |
0 The brace-expansion library versions prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10 contain a vulnerability where crafted brace patterns can exhaust the native stack during parsing. This occurs because the parseCommaParts function recursively processes brace groups and uses push.apply with very large arrays, leading to stack exhaustion and potential Node.js process termination. This results in a denial of service condition. The issue is fixed in the specified versions. Join the discussion | CVE Database V5 | 09/28/2026, 20:50:59 UTC Added: 09/28/2026, 21:03:53 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.19.47. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:66371 Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Join the discussion | GCVE Database | 09/16/2026, 04:56:34 UTC Added: 08/05/2026, 15:30:56 UTC |
0 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. Join the discussion | CVE Database V5 | 08/03/2026, 16:33:36 UTC Added: 08/03/2026, 17:18:39 UTC |
0 CVE-2026-14257 is a high-severity vulnerability in the juliangruber brace-expansion library (versions up to 5.0.7) that allows an attacker to cause uncontrolled memory consumption. The expand() function limits the number of results but not their length, enabling crafted inputs with many chained brace groups to exhaust memory and crash the Node.js process with an uncatchable out-of-memory error. This denial-of-service condition cannot be caught by try/catch and results in a fatal process termination. The vulnerability affects applications that pass attacker-controlled strings to brace-expansion.expand(), including via minimatch or glob patterns. A patch has been released that bounds the total output length to prevent unbounded memory growth. Join the discussion | CVE Database V5 | 07/24/2026, 21:53:14 UTC Added: 07/23/2026, 13:22:42 UTC |
0 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work. Join the discussion | CVE Database V5 | 06/30/2026, 08:30:34 UTC Added: 06/30/2026, 09:52:01 UTC |
0 This update includes the following RPMs: nodejs24: * nodejs24-24.15.0-1.hum1 (aarch64, x86_64) * nodejs24-bin-24.15.0-1.hum1 (noarch) * nodejs24-devel-24.15.0-1.hum1 (aarch64, x86_64) * nodejs24-docs-24.15.0-1.hum1 (noarch) * nodejs24-full-i18n-24.15.0-1.hum1 (aarch64, x86_64) * nodejs24-libs-24.15.0-1.hum1 (aarch64, x86_64) * nodejs24-npm-11.12.1-1.24.15.0.1.hum1 (noarch) * nodejs24-npm-bin-24.15.0-1.hum1 (noarch) * v8-13.6-devel-13.6.233.17-1.24.15.0.1.hum1 (aarch64, x86_64) * nodejs24-24.15.0-1.hum1.src (src) Join the discussion | GCVE Database | 05/05/2026, 20:33:28 UTC Added: 05/29/2026, 21:01:41 UTC |
0 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used. Join the discussion | CVE Database V5 | 03/27/2026, 14:04:52 UTC Added: 03/27/2026, 14:30:51 UTC |
0 CVE-2026-25547 is a critical denial of service vulnerability in versions of the @isaacs/brace-expansion library prior to 5.0.1. The issue arises from inefficient handling of numeric brace ranges, where repeated ranges cause exponential growth in expansion attempts, leading to excessive CPU and memory consumption. This can crash Node.js processes using the vulnerable library without requiring authentication or user interaction. The vulnerability has a CVSS 4.0 base score of 9.2, indicating critical severity. It affects applications and services that incorporate this library for pattern expansion, particularly in JavaScript/TypeScript environments. Join the discussion | CVE Database V5 | 02/04/2026, 21:51:17 UTC Added: 02/04/2026, 22:00:09 UTC |
Showing 1 to 10 of 11 results