{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-14257",
        "tracking": {
            "current_release_date": "2026-08-24T11:02:18.222308Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-14257",
            "initial_release_date": "2026-07-23T13:40:52.011887Z",
            "revision_history": [
                {
                    "date": "2026-07-23T13:40:52.011887Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-23T13:40:53.059807Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-07-23T14:33:48.875506Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-23T14:33:51.734029Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-23T15:44:29.765529Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-07-24T08:17:40.997289Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Products connected (25).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-07-24T15:23:31.474031Z",
                    "number": "7",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-07-24T15:23:34.165516Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-24T22:40:02.022660Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-07-24T22:40:12.527597Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-25T00:20:56.312944Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-07-25T12:44:42.368942Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (2)."
                },
                {
                    "date": "2026-07-31T19:39:56.665925Z",
                    "number": "13",
                    "summary": "References created (6)."
                },
                {
                    "date": "2026-07-31T19:40:09.549523Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-01T00:21:24.194067Z",
                    "number": "15",
                    "summary": "Products created (4).| Products removed (1).| References created (6)."
                },
                {
                    "date": "2026-08-05T12:37:39.377105Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (4).| Product Remediations created (4).| Products created (1).| Product Identifiers removed (2).| References created (13).| CWES updated (1)."
                },
                {
                    "date": "2026-08-05T12:37:47.837632Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-07T18:27:01.181902Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| CWES updated (1)."
                },
                {
                    "date": "2026-08-07T18:27:12.622172Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-08T06:22:53.175922Z",
                    "number": "20",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| CWES updated (1)."
                },
                {
                    "date": "2026-08-12T12:43:54.451962Z",
                    "number": "21",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (5).| Product Remediations created (6).| Products created (2).| Product Identifiers removed (2).| References created (12).| CWES updated (1)."
                },
                {
                    "date": "2026-08-13T00:45:27.201077Z",
                    "number": "22",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (5).| Product Remediations created (6).| Products created (2).| Product Identifiers removed (2).| References created (12).| CWES updated (1)."
                },
                {
                    "date": "2026-08-13T11:49:06.889824Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-08-13T11:49:08.394098Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-14T12:06:41.768360Z",
                    "number": "25",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-08-14T12:06:43.142367Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-14T12:27:30.413064Z",
                    "number": "27",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| Product Remediations created (5).| Product Identifiers created (4).| Product Identifiers removed (4).| References created (28).| CWES updated (1)."
                },
                {
                    "date": "2026-08-15T00:22:32.447659Z",
                    "number": "28",
                    "summary": "Products removed (1)."
                },
                {
                    "date": "2026-08-15T15:59:45.246206Z",
                    "number": "29",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-08-17T12:26:20.764825Z",
                    "number": "30",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-08-17T12:26:22.046058Z",
                    "number": "31",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-18T06:08:03.708490Z",
                    "number": "32",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (39).| Product Remediations created (24).| Products created (11).| Product Identifiers removed (27).| References created (12).| CWES updated (1)."
                },
                {
                    "date": "2026-08-18T09:29:40.748107Z",
                    "number": "33",
                    "summary": "References created (3)."
                },
                {
                    "date": "2026-08-18T13:27:29.664830Z",
                    "number": "34",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T10:33:18.777779Z",
                    "number": "35",
                    "summary": "Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-08-19T10:33:20.861582Z",
                    "number": "36",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T12:06:10.518822Z",
                    "number": "37",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (11).| References created (3)."
                },
                {
                    "date": "2026-08-19T12:06:13.130900Z",
                    "number": "38",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T13:13:18.844278Z",
                    "number": "39",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Product Remediations created (4).| References created (23).| CWES updated (1)."
                },
                {
                    "date": "2026-08-19T13:13:20.532254Z",
                    "number": "40",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T13:14:39.072915Z",
                    "number": "41",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Product Remediations created (4).| References created (21).| CWES updated (1)."
                },
                {
                    "date": "2026-08-21T08:21:03.737306Z",
                    "number": "42",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-08-21T12:28:20.412566Z",
                    "number": "43",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Product Remediations created (4).| Product Identifiers created (2).| Product Identifiers removed (2).| References created (34).| CWES updated (1)."
                },
                {
                    "date": "2026-08-21T12:28:23.658112Z",
                    "number": "44",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-24T09:53:09.524549Z",
                    "number": "45",
                    "summary": "Source connected.| CVE status created. (valid)"
                }
            ],
            "status": "interim",
            "version": "45"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.22",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.22",
                                    "product_id": "CSAFPID-9012403"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <12.1.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <12.1.10",
                                    "product_id": "CSAFPID-9012404"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bamboo"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center <10.4.2",
                                "product": {
                                    "name": "vers:unknown/data center <10.4.2",
                                    "product_id": "CSAFPID-9012406"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.6",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.6",
                                    "product_id": "CSAFPID-9012408"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.4.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.4.23",
                                    "product_id": "CSAFPID-9012407"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bitbucket"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.15",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.15",
                                    "product_id": "CSAFPID-9012410"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.2.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.2.23",
                                    "product_id": "CSAFPID-9012409"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Confluence"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012413"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Crucible"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012411"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Fisheye"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.3.24",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.3.24",
                                    "product_id": "CSAFPID-9012405"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <11.3.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <11.3.10",
                                    "product_id": "CSAFPID-9012414"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jira"
                    }
                ],
                "category": "vendor",
                "name": "Atlassian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8",
                                "product": {
                                    "name": "vers:unknown/8",
                                    "product_id": "CSAFPID-1189183",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/2.1",
                                        "product": {
                                            "name": "vers:rpm/2.1",
                                            "product_id": "CSAFPID-8942316",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:ansible_portal:2.1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Ansible Automation Platform 2.1"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/2.2",
                                        "product": {
                                            "name": "vers:rpm/2.2",
                                            "product_id": "CSAFPID-8874741",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:ansible_portal:2.2"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Ansible Automation Platform 2.2"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1787047114",
                                        "product": {
                                            "name": "vers:oci/1787047114",
                                            "product_id": "CSAFPID-9013139",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/automation-portal@sha256%3A1ea7e595d09aba21055ea861f403dcac6bcb031dcfb8166f917b695d7829c5ab?arch=amd64&repository_url=registry.redhat.io/ansible-automation-platform/automation-portal&tag=1787047114"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1787047188",
                                        "product": {
                                            "name": "vers:oci/1787047188",
                                            "product_id": "CSAFPID-9013164",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/automation-portal@sha256%3A9595023cdb01463dcab779b7e041987c6d00769bb174f43aadd477293a521508?arch=amd64&repository_url=registry.redhat.io/ansible-automation-platform/automation-portal&tag=1787047188"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-portal"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/2",
                                        "product": {
                                            "name": "vers:rpm/2",
                                            "product_id": "CSAFPID-2993424",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:discovery:2::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Discovery 2"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1786638573",
                                        "product": {
                                            "name": "vers:oci/1786638573",
                                            "product_id": "CSAFPID-8987713",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/discovery-server-rhel9@sha256%3A43f1ad539e71187687fe816e256d2c016ab1048d9e56004e19e621b3518bde04?arch=amd64&repository_url=registry.redhat.io/discovery/discovery-server-rhel9&tag=1786638573"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "discovery-server-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oci/1786634825",
                                        "product": {
                                            "name": "vers:oci/1786634825",
                                            "product_id": "CSAFPID-8987714",
                                            "product_identification_helper": {
                                                "purl": "pkg:oci/discovery-ui-rhel9@sha256%3A8268709ddc6c9537cb5f0ab978b7afc507fdbf035723327e3f542b10eef2b25c?arch=arm64&repository_url=registry.redhat.io/discovery/discovery-ui-rhel9&tag=1786634825"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "discovery-ui-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Discovery"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.2",
                                        "product": {
                                            "name": "vers:rpm/10.2",
                                            "product_id": "CSAFPID-7372357",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/o:redhat:enterprise_linux:10.2"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Enterprise Linux AppStream (v. 10)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.2",
                                        "product": {
                                            "name": "vers:rpm/10.2",
                                            "product_id": "CSAFPID-8597124",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/o:redhat:enterprise_linux:10.2"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Enterprise Linux Extensions Channel (v. 10)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002676",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002677",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-debuginfo@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-debuginfo"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002678",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-devel@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-devel"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002679",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-docs@22.23.1-6.el10_2?arch=noarch&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-docs"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002680",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-full-i18n@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-full-i18n"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002681",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-libs@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-libs"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002682",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-libs-debuginfo@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-libs-debuginfo"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.9.8-1.22.23.1.6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/10.9.8-1.22.23.1.6.el10_2",
                                            "product_id": "CSAFPID-9002683",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs-npm@10.9.8-1.22.23.1.6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs-npm"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002684",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs22@22.23.1-6.el10_2?arch=src&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs22"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002685",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs22-debuginfo@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs22-debuginfo"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/22.23.1-6.el10_2",
                                        "product": {
                                            "name": "vers:rpm/22.23.1-6.el10_2",
                                            "product_id": "CSAFPID-9002686",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs22-debugsource@22.23.1-6.el10_2?arch=x86_64&epoch=1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs22-debugsource"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/1.1.2-1.el10_2",
                                        "product": {
                                            "name": "vers:rpm/1.1.2-1.el10_2",
                                            "product_id": "CSAFPID-9038968",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/rh-podman-desktop@1.1.2-1.el10_2?arch=x86_64"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rh-podman-desktop"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/1",
                                        "product": {
                                            "name": "vers:rpm/1",
                                            "product_id": "CSAFPID-6154979",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:hummingbird:1"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat Hardened Images"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/12.4.6-0.4.hum1",
                                        "product": {
                                            "name": "vers:rpm/12.4.6-0.4.hum1",
                                            "product_id": "CSAFPID-8936380",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/grafana12.4@12.4.6-0.4.hum1?arch=x86_64&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana12.4"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/24.18.1-0.2.1.hum1",
                                        "product": {
                                            "name": "vers:rpm/24.18.1-0.2.1.hum1",
                                            "product_id": "CSAFPID-8971128",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs24@24.18.1-0.2.1.hum1?arch=x86_64&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs24"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/24.18.1-0.2.1.hum1",
                                        "product": {
                                            "name": "vers:rpm/24.18.1-0.2.1.hum1",
                                            "product_id": "CSAFPID-8971129",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs24-bin@24.18.1-0.2.1.hum1?arch=noarch&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs24-bin"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/26.7.0-1.5.2.hum1",
                                        "product": {
                                            "name": "vers:rpm/26.7.0-1.5.2.hum1",
                                            "product_id": "CSAFPID-8976326",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs26@26.7.0-1.5.2.hum1?arch=x86_64&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs26"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/26.7.0-1.5.2.hum1",
                                        "product": {
                                            "name": "vers:rpm/26.7.0-1.5.2.hum1",
                                            "product_id": "CSAFPID-8976327",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/nodejs26-bin@26.7.0-1.5.2.hum1?arch=noarch&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "nodejs26-bin"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Hardened Images"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317177",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:oracle:linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Oracle Linux"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330300",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:resf:rocky_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "RESF Rocky Linux"
                    }
                ],
                "category": "vendor",
                "name": "RESF"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5197899",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:azl3_python-tensorboard_2.16.2-6:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Open Source Software"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<=5.0.7",
                                "product": {
                                    "name": "vers:semver/<=5.0.7",
                                    "product_id": "CSAFPID-8884988"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.11",
                                "product": {
                                    "name": "vers:unknown/1.1.11",
                                    "product_id": "CSAFPID-2903082"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<1.1.17",
                                "product": {
                                    "name": "vers:unknown/>=0|<1.1.17",
                                    "product_id": "CSAFPID-8920816"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.0.0|<2.1.3",
                                "product": {
                                    "name": "vers:unknown/>=2.0.0|<2.1.3",
                                    "product_id": "CSAFPID-8920815"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.0.3",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.0.3",
                                    "product_id": "CSAFPID-8920814"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=4.0.0|<5.0.8",
                                "product": {
                                    "name": "vers:unknown/>=4.0.0|<5.0.8",
                                    "product_id": "CSAFPID-8920813"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0",
                                    "product_id": "CSAFPID-3722668"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.1",
                                "product": {
                                    "name": "vers:unknown/v1.0.1",
                                    "product_id": "CSAFPID-3722669"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-3722670"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.1",
                                "product": {
                                    "name": "vers:unknown/v1.1.1",
                                    "product_id": "CSAFPID-3722671"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.10",
                                "product": {
                                    "name": "vers:unknown/v1.1.10",
                                    "product_id": "CSAFPID-3722672"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.11",
                                "product": {
                                    "name": "vers:unknown/v1.1.11",
                                    "product_id": "CSAFPID-3722673"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.2",
                                "product": {
                                    "name": "vers:unknown/v1.1.2",
                                    "product_id": "CSAFPID-3722674"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.3",
                                "product": {
                                    "name": "vers:unknown/v1.1.3",
                                    "product_id": "CSAFPID-3722675"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.4",
                                "product": {
                                    "name": "vers:unknown/v1.1.4",
                                    "product_id": "CSAFPID-3722676"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.5",
                                "product": {
                                    "name": "vers:unknown/v1.1.5",
                                    "product_id": "CSAFPID-3722677"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.6",
                                "product": {
                                    "name": "vers:unknown/v1.1.6",
                                    "product_id": "CSAFPID-3722678"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.7",
                                "product": {
                                    "name": "vers:unknown/v1.1.7",
                                    "product_id": "CSAFPID-3722679"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.8",
                                "product": {
                                    "name": "vers:unknown/v1.1.8",
                                    "product_id": "CSAFPID-3722680"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.9",
                                "product": {
                                    "name": "vers:unknown/v1.1.9",
                                    "product_id": "CSAFPID-3722681"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.0",
                                "product": {
                                    "name": "vers:unknown/v2.0.0",
                                    "product_id": "CSAFPID-3722682"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v2.0.1",
                                "product": {
                                    "name": "vers:unknown/v2.0.1",
                                    "product_id": "CSAFPID-3722683"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v3.0.0",
                                "product": {
                                    "name": "vers:unknown/v3.0.0",
                                    "product_id": "CSAFPID-3722684"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.0",
                                "product": {
                                    "name": "vers:unknown/v4.0.0",
                                    "product_id": "CSAFPID-3722685"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v4.0.1",
                                "product": {
                                    "name": "vers:unknown/v4.0.1",
                                    "product_id": "CSAFPID-8581289"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.2",
                                "product": {
                                    "name": "vers:unknown/v5.0.2",
                                    "product_id": "CSAFPID-8581288"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.3",
                                "product": {
                                    "name": "vers:unknown/v5.0.3",
                                    "product_id": "CSAFPID-8581287"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.4",
                                "product": {
                                    "name": "vers:unknown/v5.0.4",
                                    "product_id": "CSAFPID-8581286"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.5",
                                "product": {
                                    "name": "vers:unknown/v5.0.5",
                                    "product_id": "CSAFPID-8581285"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.6",
                                "product": {
                                    "name": "vers:unknown/v5.0.6",
                                    "product_id": "CSAFPID-8581284"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v5.0.7",
                                "product": {
                                    "name": "vers:unknown/v5.0.7",
                                    "product_id": "CSAFPID-8889079"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "brace-expansion"
                    }
                ],
                "category": "vendor",
                "name": "juliangruber"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-2909840"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-brace-expansion"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-2909841"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-brace-expansion"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-14257",
            "cwe": {
                "id": "CWE-770",
                "name": "Allocation of Resources Without Limits or Throttling"
            },
            "flags": [
                {
                    "label": "vulnerable_code_not_present",
                    "product_ids": [
                        "CSAFPID-8987713"
                    ]
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/14xxx/CVE-2026-14257.json"
                },
                {
                    "category": "description",
                    "text": "brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-14257"
                },
                {
                    "category": "description",
                    "text": "brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-14257.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Summary\n\n`expand()` bounds the *number* of results it produces (the `max` option,\n`100_000` by default) but not their *length*. By chaining many brace groups,\nan attacker keeps the result count under `max` while making every result grow\nwith the number of groups. Building `max` long results — plus the intermediate\narrays combined at each brace group — exhausts memory and crashes the Node\nprocess with an **uncatchable** out-of-memory error. `try/catch` around\n`expand()` does not help: the fatal error terminates the process.\n\nA ~7.5 KB input (`'{a,b}'.repeat(1500)`) is enough to crash a default Node\nprocess.\n\n### Details\n\nFor `N` chained brace groups such as `'{a,b}'.repeat(N)`:\n\n- the result count is `2^N`, immediately capped at `max` (`100_000`), so the\n  `max` protection appears to hold, but\n- each result is `N` characters long, so the total output size is\n  `max × N` characters, which grows without bound in `N`.\n\n`expand_` combines each brace set with the fully-expanded tail:\n\n```js\nconst post = m.post.length ? expand_(m.post, max, false) : ['']\n...\nfor (let j = 0; j < N.length; j++) {\n  for (let k = 0; k < post.length && expansions.length < max; k++) {\n    const expansion = pre + N[j] + post[k]   // grows one group longer per level\n    ...\n    expansions.push(expansion)\n  }\n}\n```\n\nThe loop guard `expansions.length < max` limits how many strings are built, but\nnothing limits how long they get. Each recursion level materializes another\narray of up to `max` strings, one character longer than the level below, and —\nbecause V8 represents `pre + N[j] + post[k]` as a cons-string (rope) that\nreferences `post[k]` — those intermediate strings stay reachable through the\nwhole chain. Memory therefore scales with `max × N`.\n\nMeasured on `5.0.7` (`'{a,b}'.repeat(N)`, default `max`):\n\n| groups (N) | input bytes | result count | peak RSS |\n|---|---|---|---|\n| 20 | 100 | 100,000 | ~80 MB |\n| 50 | 250 | 100,000 | ~214 MB |\n| 100 | 500 | 100,000 | ~409 MB |\n| 300 | 1,500 | 100,000 | ~1,148 MB |\n| 1500 | 7,500 | — | **OOM crash** |\n\n### Proof of concept\n\n```js\nconst { expand } = require('brace-expansion')\n\n// ~7.5 KB input — crashes the process with a fatal, uncatchable OOM:\n//   FATAL ERROR: ... JavaScript heap out of memory\ntry {\n  expand('{a,b}'.repeat(1500))\n} catch (e) {\n  // never reached — the process is already dead\n}\n```\n\n### Impact\n\nAny application that passes attacker-influenced strings to\n`brace-expansion.expand()` — directly, or transitively via `minimatch` / `glob`\nbrace patterns — can be crashed by a small request. Because the failure is a\nfatal V8 out-of-memory error rather than a thrown exception, it cannot be caught\nand it takes down the whole worker/process, denying service.\n\n### Remediation\n\nUpgrade to a patched release. The fix bounds the total number of characters a\nsingle `expand()` call may accumulate (`EXPANSION_MAX_LENGTH`, default\n`4_000_000`, configurable via a new `maxLength` option), applied inside the\noutput-building loops so intermediate arrays are bounded too. Once the limit is\nreached, output is truncated — consistent with how `max` already truncates —\ninstead of growing without bound. The limit sits well above any realistic\nexpansion (100,000 results hitting `max` measure ~1M characters), so legitimate\ninput is unaffected.\n\nAfter the fix, `'{a,b}'.repeat(1500)` returns a bounded, truncated result in\n~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB\nheap.\n\nThe fix bounds memory but the algorithm still rebuilds intermediate arrays at\neach level (roughly `O(N × maxLength)` work on this input class). A streaming\nrewrite that produces output in `O(total output size)` can be a non-urgent\nfollow-up.\n\nIf immediate upgrade isn't possible, avoid passing untrusted input to\n`expand()` / glob brace patterns, or pass a small explicit `max` **and**\n`maxLength`.",
                    "title": "github - https://api.github.com/advisories/GHSA-mh99-v99m-4gvg"
                },
                {
                    "category": "description",
                    "text": "### Summary\n\n`expand()` bounds the *number* of results it produces (the `max` option,\n`100_000` by default) but not their *length*. By chaining many brace groups,\nan attacker keeps the result count under `max` while making every result grow\nwith the number of groups. Building `max` long results — plus the intermediate\narrays combined at each brace group — exhausts memory and crashes the Node\nprocess with an **uncatchable** out-of-memory error. `try/catch` around\n`expand()` does not help: the fatal error terminates the process.\n\nA ~7.5 KB input (`'{a,b}'.repeat(1500)`) is enough to crash a default Node\nprocess.\n\n### Details\n\nFor `N` chained brace groups such as `'{a,b}'.repeat(N)`:\n\n- the result count is `2^N`, immediately capped at `max` (`100_000`), so the\n  `max` protection appears to hold, but\n- each result is `N` characters long, so the total output size is\n  `max × N` characters, which grows without bound in `N`.\n\n`expand_` combines each brace set with the fully-expanded tail:\n\n```js\nconst post = m.post.length ? expand_(m.post, max, false) : ['']\n...\nfor (let j = 0; j < N.length; j++) {\n  for (let k = 0; k < post.length && expansions.length < max; k++) {\n    const expansion = pre + N[j] + post[k]   // grows one group longer per level\n    ...\n    expansions.push(expansion)\n  }\n}\n```\n\nThe loop guard `expansions.length < max` limits how many strings are built, but\nnothing limits how long they get. Each recursion level materializes another\narray of up to `max` strings, one character longer than the level below, and —\nbecause V8 represents `pre + N[j] + post[k]` as a cons-string (rope) that\nreferences `post[k]` — those intermediate strings stay reachable through the\nwhole chain. Memory therefore scales with `max × N`.\n\nMeasured on `5.0.7` (`'{a,b}'.repeat(N)`, default `max`):\n\n| groups (N) | input bytes | result count | peak RSS |\n|---|---|---|---|\n| 20 | 100 | 100,000 | ~80 MB |\n| 50 | 250 | 100,000 | ~214 MB |\n| 100 | 500 | 100,000 | ~409 MB |\n| 300 | 1,500 | 100,000 | ~1,148 MB |\n| 1500 | 7,500 | — | **OOM crash** |\n\n### Proof of concept\n\n```js\nconst { expand } = require('brace-expansion')\n\n// ~7.5 KB input — crashes the process with a fatal, uncatchable OOM:\n//   FATAL ERROR: ... JavaScript heap out of memory\ntry {\n  expand('{a,b}'.repeat(1500))\n} catch (e) {\n  // never reached — the process is already dead\n}\n```\n\n### Impact\n\nAny application that passes attacker-influenced strings to\n`brace-expansion.expand()` — directly, or transitively via `minimatch` / `glob`\nbrace patterns — can be crashed by a small request. Because the failure is a\nfatal V8 out-of-memory error rather than a thrown exception, it cannot be caught\nand it takes down the whole worker/process, denying service.\n\n### Remediation\n\nUpgrade to a patched release. The fix bounds the total number of characters a\nsingle `expand()` call may accumulate (`EXPANSION_MAX_LENGTH`, default\n`4_000_000`, configurable via a new `maxLength` option), applied inside the\noutput-building loops so intermediate arrays are bounded too. Once the limit is\nreached, output is truncated — consistent with how `max` already truncates —\ninstead of growing without bound. The limit sits well above any realistic\nexpansion (100,000 results hitting `max` measure ~1M characters), so legitimate\ninput is unaffected.\n\nAfter the fix, `'{a,b}'.repeat(1500)` returns a bounded, truncated result in\n~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB\nheap.\n\nThe fix bounds memory but the algorithm still rebuilds intermediate arrays at\neach level (roughly `O(N × maxLength)` work on this input class). A streaming\nrewrite that produces output in `O(total output size)` can be a non-urgent\nfollow-up.\n\nIf immediate upgrade isn't possible, avoid passing untrusted input to\n`expand()` / glob brace patterns, or pass a small explicit `max` **and**\n`maxLength`.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-mh99-v99m-4gvg.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-14257"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:50290.json"
                },
                {
                    "category": "description",
                    "text": "brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Aug"
                },
                {
                    "category": "description",
                    "text": "brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54183.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54389.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54760.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:55541.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:56338.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:56357.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:57590.json"
                },
                {
                    "category": "other",
                    "text": "0.00339",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, VENDOR FIX as product remediation category, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Red Hat",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-8936380",
                    "CSAFPID-8971128",
                    "CSAFPID-8971129",
                    "CSAFPID-8976326",
                    "CSAFPID-8976327",
                    "CSAFPID-8987714",
                    "CSAFPID-9002676",
                    "CSAFPID-9002677",
                    "CSAFPID-9002678",
                    "CSAFPID-9002679",
                    "CSAFPID-9002680",
                    "CSAFPID-9002681",
                    "CSAFPID-9002682",
                    "CSAFPID-9002683",
                    "CSAFPID-9002684",
                    "CSAFPID-9002685",
                    "CSAFPID-9002686",
                    "CSAFPID-9013139",
                    "CSAFPID-9013164",
                    "CSAFPID-9038968"
                ],
                "known_affected": [
                    "CSAFPID-8884988",
                    "CSAFPID-2903082",
                    "CSAFPID-3722668",
                    "CSAFPID-3722669",
                    "CSAFPID-3722670",
                    "CSAFPID-3722671",
                    "CSAFPID-3722672",
                    "CSAFPID-3722673",
                    "CSAFPID-3722674",
                    "CSAFPID-3722675",
                    "CSAFPID-3722676",
                    "CSAFPID-3722677",
                    "CSAFPID-3722678",
                    "CSAFPID-3722679",
                    "CSAFPID-3722680",
                    "CSAFPID-3722681",
                    "CSAFPID-3722682",
                    "CSAFPID-3722683",
                    "CSAFPID-3722684",
                    "CSAFPID-3722685",
                    "CSAFPID-8581284",
                    "CSAFPID-8581285",
                    "CSAFPID-8581286",
                    "CSAFPID-8581287",
                    "CSAFPID-8581288",
                    "CSAFPID-8581289",
                    "CSAFPID-8889079",
                    "CSAFPID-2909840",
                    "CSAFPID-2909841",
                    "CSAFPID-8920813",
                    "CSAFPID-8920814",
                    "CSAFPID-8920815",
                    "CSAFPID-8920816",
                    "CSAFPID-5197899",
                    "CSAFPID-1189183",
                    "CSAFPID-1317175",
                    "CSAFPID-1317177",
                    "CSAFPID-1330300",
                    "CSAFPID-9012403",
                    "CSAFPID-9012404",
                    "CSAFPID-9012405",
                    "CSAFPID-9012406",
                    "CSAFPID-9012407",
                    "CSAFPID-9012408",
                    "CSAFPID-9012409",
                    "CSAFPID-9012410",
                    "CSAFPID-9012411",
                    "CSAFPID-9012413",
                    "CSAFPID-9012414"
                ],
                "known_not_affected": [
                    "CSAFPID-8987713"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:57590.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0325"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/14xxx/CVE-2026-14257.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-14257.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=30000"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-mh99-v99m-4gvg"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-mh99-v99m-4gvg.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:50290.json"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Aug"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54183.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54389.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2816.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:54760.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=40000"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:55541.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:56338.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:56357.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://vulnerabilities.ncsc.nl/manual/CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://www.npmjs.com/package/brace-expansion"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/juliangruber/brace-expansion"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14257.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/pull/129"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/pull/130"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/pull/136"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506433"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-14257"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:50290"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-69152"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-69153"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://images.redhat.com/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50290.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:54183"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54183.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:54389"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54389.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2816.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2816"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:54371"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:54760"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2025-4330"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-11940"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-13676"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-13757"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-14164"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-34993"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-41989"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-6477"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-69243"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-69244"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-73086"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-73088"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-73089"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-8643"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-9595"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54760.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://oss.oracle.com/pipermail/el-errata/2026-August/021605.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:55541"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/#important"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510722"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510801"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55541.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:55601"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-55541.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-55603.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://errata.build.resf.org/RLSA-2026:55541"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-55601.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2923"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://confluence.atlassian.com/security/security-bulletin-august-18-2026-1821999768.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:56338"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-12143"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-44705"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-45623"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-46625"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-54272"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-69192"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56338.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:56357"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56357.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:57590"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455470"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476810"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477081"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477914"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487050"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487946"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488480"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488934"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489661"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493633"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494197"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494813"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498116"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498120"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498122"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498127"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499682"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500656"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500695"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507595"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2510719"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/RHEL-238929"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_57590.json"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
                    "product_ids": [
                        "CSAFPID-6154979",
                        "CSAFPID-8936380"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:50290"
                },
                {
                    "category": "workaround",
                    "details": "Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion.\n\nWhere possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output.\n\nAs an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage.",
                    "product_ids": [
                        "CSAFPID-6154979",
                        "CSAFPID-8936380",
                        "CSAFPID-8971128",
                        "CSAFPID-8971129",
                        "CSAFPID-8976326",
                        "CSAFPID-8976327",
                        "CSAFPID-2993424",
                        "CSAFPID-8987713",
                        "CSAFPID-8987714",
                        "CSAFPID-7372357",
                        "CSAFPID-9002676",
                        "CSAFPID-9002677",
                        "CSAFPID-9002678",
                        "CSAFPID-9002679",
                        "CSAFPID-9002680",
                        "CSAFPID-9002681",
                        "CSAFPID-9002682",
                        "CSAFPID-9002683",
                        "CSAFPID-9002684",
                        "CSAFPID-9002685",
                        "CSAFPID-9002686",
                        "CSAFPID-8942316",
                        "CSAFPID-9013139",
                        "CSAFPID-8874741",
                        "CSAFPID-9013164",
                        "CSAFPID-8597124",
                        "CSAFPID-9038968"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
                    "product_ids": [
                        "CSAFPID-6154979",
                        "CSAFPID-8971128",
                        "CSAFPID-8971129"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:54183"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
                    "product_ids": [
                        "CSAFPID-6154979",
                        "CSAFPID-8976326",
                        "CSAFPID-8976327"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:54389"
                },
                {
                    "category": "vendor_fix",
                    "details": "The containers required to run Discovery can be installed through discovery-installer\nRPM. See the official documentation for more details.",
                    "product_ids": [
                        "CSAFPID-2993424",
                        "CSAFPID-8987714"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:54760"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-7372357",
                        "CSAFPID-9002676",
                        "CSAFPID-9002677",
                        "CSAFPID-9002678",
                        "CSAFPID-9002679",
                        "CSAFPID-9002680",
                        "CSAFPID-9002681",
                        "CSAFPID-9002682",
                        "CSAFPID-9002683",
                        "CSAFPID-9002684",
                        "CSAFPID-9002685",
                        "CSAFPID-9002686"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:55541"
                },
                {
                    "category": "vendor_fix",
                    "details": "For more about Ansible plugins for Red Hat Developer Hub, see References links",
                    "product_ids": [
                        "CSAFPID-8942316",
                        "CSAFPID-9013139"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:56338"
                },
                {
                    "category": "vendor_fix",
                    "details": "For more about Ansible plugins for Red Hat Developer Hub, see References links",
                    "product_ids": [
                        "CSAFPID-8874741",
                        "CSAFPID-9013164"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:56357"
                },
                {
                    "category": "vendor_fix",
                    "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-8597124",
                        "CSAFPID-9038968"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:57590"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1189183",
                        "CSAFPID-1317175",
                        "CSAFPID-1317177",
                        "CSAFPID-1330300",
                        "CSAFPID-2903082",
                        "CSAFPID-2909840",
                        "CSAFPID-2909841",
                        "CSAFPID-3722668",
                        "CSAFPID-3722669",
                        "CSAFPID-3722670",
                        "CSAFPID-3722671",
                        "CSAFPID-3722672",
                        "CSAFPID-3722673",
                        "CSAFPID-3722674",
                        "CSAFPID-3722675",
                        "CSAFPID-3722676",
                        "CSAFPID-3722677",
                        "CSAFPID-3722678",
                        "CSAFPID-3722679",
                        "CSAFPID-3722680",
                        "CSAFPID-3722681",
                        "CSAFPID-3722682",
                        "CSAFPID-3722683",
                        "CSAFPID-3722684",
                        "CSAFPID-3722685",
                        "CSAFPID-5197899",
                        "CSAFPID-8581284",
                        "CSAFPID-8581285",
                        "CSAFPID-8581286",
                        "CSAFPID-8581287",
                        "CSAFPID-8581288",
                        "CSAFPID-8581289",
                        "CSAFPID-8884988",
                        "CSAFPID-8889079",
                        "CSAFPID-8920813",
                        "CSAFPID-8920814",
                        "CSAFPID-8920815",
                        "CSAFPID-8920816",
                        "CSAFPID-9012403",
                        "CSAFPID-9012404",
                        "CSAFPID-9012405",
                        "CSAFPID-9012406",
                        "CSAFPID-9012407",
                        "CSAFPID-9012408",
                        "CSAFPID-9012409",
                        "CSAFPID-9012410",
                        "CSAFPID-9012411",
                        "CSAFPID-9012413",
                        "CSAFPID-9012414"
                    ]
                }
            ],
            "title": "CVE-2026-14257"
        }
    ]
}