npm vulnerability intelligence

brace-expansion NPM Package
Vulnerability Check

Brace expansion as known from sh/bash

High severity MIT v5.0.6
Vulnerability Analysis OSV Live

brace-expansion

v5.0.6 · MIT · 521,410,596 dl/wk

Advisory Breakdown

Critical 0
High 1
Moderate 2
Low 1

Severity Rating

High severity

4 advisories

High severity

Weekly downloads

521,410,596

Total advisories

4

Latest version

5.0.6

License

MIT

Known advisories

OSV records for the npm ecosystem

4
GHSA-832h-xg76-4gv6 CVE-2017-18077 high

ReDoS in brace-expansion

Affected: >=0 <1.1.7 Fixed in: 1.1.7 Updated Nov 8, 2023
View source
GHSA-f886-m6hf-6m8v CVE-2026-33750 moderate

brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Affected: >=4.0.0 <5.0.5, >=3.0.0 <3.0.2, >=2.0.0 <2.0.3, >=0 <1.1.13 Fixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13 Updated Mar 27, 2026
View source
GHSA-jxxr-4gwj-5jf2 CVE-2026-45149 moderate

brace-expansion: Large numeric range defeats documented `max` DoS protection

Affected: >=5.0.0 <5.0.6 Fixed in: 5.0.6 Updated May 20, 2026
View source
GHSA-v6h2-p8h4-qcjw CVE-2025-5889 low

brace-expansion Regular Expression Denial of Service vulnerability

Affected: >=2.0.0 <2.0.2, >=1.0.0 <1.1.12, >=3.0.0 <3.0.1, >=4.0.0 <4.0.1 Fixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1 Updated Feb 4, 2026
View source

Checked May 22, 2026, 7:07 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
brace-expansion
Ecosystem
npm
Latest version
5.0.6
License
MIT
Weekly downloads
521,410,596

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 5/22/2026, 7:07:46 PM