Skip to content

[GHSA-v6h2-p8h4-qcjw] brace-expansion Regular Expression Denial of Service vulnerability #5708

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

rakleed
Copy link

@rakleed rakleed commented Jun 11, 2025

Updates

  • Affected products
  • CVSS v3
  • CVSS v4

Comments
https://github.com/juliangruber/brace-expansion/releases

@Copilot Copilot AI review requested due to automatic review settings June 11, 2025 14:13
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the advisory for the brace-expansion Regular Expression Denial of Service vulnerability by revising metadata and affected version details.

  • Updated the modified timestamp.
  • Adjusted the CVSS V4 severity score and version details in the affected section.
  • Added the database_specific field to denote the last known affected version range.
Comments suppressed due to low confidence (1)

advisories/github-reviewed/2025/06/GHSA-v6h2-p8h4-qcjw/GHSA-v6h2-p8h4-qcjw.json:28

  • Consider clarifying in the documentation the use of version '0' for the 'introduced' field, as it deviates from typical semantic versioning conventions.
"introduced": "0"

@rakleed rakleed closed this Jun 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant