| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-33750 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | The brace-expansion library generates arbitrary strings containing a c ... |
| CVE-2026-25547 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-e ... |
| CVE-2025-5889 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | fixed | A vulnerability was found in juliangruber brace-expansion up to 1.1.11 ... |