[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash - #8870
Conversation
|
Hi there @juliangruber! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
Restricts GHSA-mh99-v99m-4gvg to the affected brace-expansion 5.x release line.
Changes:
- Sets the affected range to
5.0.0–5.0.7. - Removes the redundant last-known affected range.
- Updates the modification timestamp.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
This update is incorrect - the advisory covers all versions, and will be updated to reflect that by #8832 |
Updates
Comments
There are security patches for the 1.x, 2.x and 3.x lines too so this should only apply to 5.x line and have separate advisories for other major versions.