CVE-2018-1109

NameCVE-2018-1109
DescriptionA vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-braces (PTS)bullseye3.0.2+~3.0.0-1fixed
bookworm3.0.2+~3.0.1-1fixed
forky, sid, trixie3.0.3+~3.0.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-bracessource(unstable)(not affected)

Notes

- node-braces <not-affected> (Vulnerable code introduced in 2.2.0)
https://snyk.io/vuln/npm:braces:20180219
Introduced by: https://github.com/micromatch/braces/commit/dcc1acab4de9a43e86ab4be4acde209ff1dca113 (2.2.0)
Fixed by: https://github.com/micromatch/braces/commit/abdafb0cae1e0c00f184abbadc692f4eaa98f451 (2.3.1)
Cf. analysis in https://bugs.debian.org/927716#38

Search for package or bug name: Reporting problems