[Git][security-tracker-team/security-tracker][master] Add new node-brace-expansion issue (CVE-2026-69152)
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 3 20:38:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
18bb5da5 by Salvatore Bonaccorso at 2026-08-03T21:37:52+02:00
Add new node-brace-expansion issue (CVE-2026-69152)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,7 +7,13 @@ CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and modi
NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
NOTE: Fixed by: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 (8.5.23)
CVE-2026-69152 (The brace-expansion library generates arbitrary strings containing a c ...)
- TODO: check
+ - node-brace-expansion <not-affected> (Incomplete fix for CVE-2026-14257 not applied)
+ NOTE: https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895
+ NOTE: https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf (v5.0.9)
+ NOTE: https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d (v3.0.3)
+ NOTE: https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac (v2.1.4)
+ NOTE: https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031 (v1.1.17)
+ NOTE: Issue exists because of a bypass of the fix for CVE-2026-14257
CVE-2026-69151 (Angular is a development platform for building mobile and desktop web ...)
TODO: check
CVE-2026-69149 (Angular is a development platform for building mobile and desktop web ...)
@@ -9060,6 +9066,7 @@ CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File Manager
CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of service via m ...)
- node-brace-expansion <unfixed> (bug #1142832)
NOTE: https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5 (v5.0.8)
+ NOTE: When fixing this issue make sure to make it complete and not open CVE-2026-69152.
CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress is vuln ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress is vulner ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18bb5da58307d36ad393dbb79bb07212a3b739df
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18bb5da58307d36ad393dbb79bb07212a3b739df
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/508ba7be/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list