Title: vulnerabilities/NVD/CVE-2026-25547 · Issue #1405 · javascript-obfuscator/javascript-obfuscator · GitHub
Open Graph Title: vulnerabilities/NVD/CVE-2026-25547 · Issue #1405 · javascript-obfuscator/javascript-obfuscator
X Title: vulnerabilities/NVD/CVE-2026-25547 · Issue #1405 · javascript-obfuscator/javascript-obfuscator
Description: brace-expansion@1.1.13 has the CVE-2026-25547 issue. Will the development team will upgrade the multimatch version? Thanks @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/br...
Open Graph Description: brace-expansion@1.1.13 has the CVE-2026-25547 issue. Will the development team will upgrade the multimatch version? Thanks @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expan...
X Description: brace-expansion@1.1.13 has the CVE-2026-25547 issue. Will the development team will upgrade the multimatch version? Thanks @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expan...
Opengraph URL: https://github.com/javascript-obfuscator/javascript-obfuscator/issues/1405
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"vulnerabilities/NVD/CVE-2026-25547","articleBody":"brace-expansion@1.1.13 has the CVE-2026-25547 issue.\nWill the development team will upgrade the multimatch version?\nThanks\n\n[@isaacs](https://github.com/isaacs)/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, [@isaacs](https://github.com/isaacs)/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.\n\n+-- javascript-obfuscator@5.4.1\n| `-- multimatch@5.0.0\n| `-- minimatch@3.1.5\n| `-- brace-expansion@1.1.13\n","author":{"url":"https://github.com/GuoqiangChen918","@type":"Person","name":"GuoqiangChen918"},"datePublished":"2026-04-09T07:25:15.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/1405/javascript-obfuscator/issues/1405"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:1ef04e32-ec72-03a7-3f44-f627f548419e |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | B5BC:A7892:6F3E44:966867:6A62DEBA |
| html-safe-nonce | 6e8ea1e01ffdef80e3524bea97d263284d2d35f76073222e284d8e564775277c |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCNUJDOkE3ODkyOjZGM0U0NDo5NjY4Njc6NkE2MkRFQkEiLCJ2aXNpdG9yX2lkIjoiMjUwMjM3NDQ0ODEwNjIzMzUzMCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 64eef3c6873dd35d4d84a5a94c9b567c17a89fd885e73555b7d9b2afa5ee1e89 |
| hovercard-subject-tag | issue:4230298821 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/javascript-obfuscator/javascript-obfuscator/1405/issue_layout |
| twitter:image | https://opengraph.githubassets.com/3862c64f6558fb3292ec0c9ea1b7321b3b5ed8c857d44eab576aa2392e54741d/javascript-obfuscator/javascript-obfuscator/issues/1405 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/3862c64f6558fb3292ec0c9ea1b7321b3b5ed8c857d44eab576aa2392e54741d/javascript-obfuscator/javascript-obfuscator/issues/1405 |
| og:image:alt | brace-expansion@1.1.13 has the CVE-2026-25547 issue. Will the development team will upgrade the multimatch version? Thanks @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expan... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | GuoqiangChen918 |
| hostname | github.com |
| expected-hostname | github.com |
| None | df33b1b61ee7b9a0af988199bfc3503c9c1acafb1f1d40e1f140ea7c84f890dd |
| turbo-cache-control | no-preview |
| go-import | github.com/javascript-obfuscator/javascript-obfuscator git https://github.com/javascript-obfuscator/javascript-obfuscator.git |
| octolytics-dimension-user_id | 23015672 |
| octolytics-dimension-user_login | javascript-obfuscator |
| octolytics-dimension-repository_id | 58360147 |
| octolytics-dimension-repository_nwo | javascript-obfuscator/javascript-obfuscator |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 58360147 |
| octolytics-dimension-repository_network_root_nwo | javascript-obfuscator/javascript-obfuscator |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | d41cd1bdb290013455c0ac430fa755621733f5eb |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width