7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether brace-expansion is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-69152
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
MEDIUM 5.3
CVE-2026-13149
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
MEDIUM 6.5
CVE-2026-45149
brace-expansion: Large numeric range defeats documented `max` DoS protection
MEDIUM 6.5
CVE-2026-33750
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
LOW 3.1
CVE-2025-5889
brace-expansion Regular Expression Denial of Service vulnerability
HIGH 7.5
CVE-2026-14257
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
HIGH 7.5
CVE-2017-18077
ReDoS in brace-expansion
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes