CVE-2026-69152

Aliases:RHSA-2026:52841RHSA-2026:54436UBUNTU-CVE-2026-69152GHSA-rgw5-rvv9-x895RHSA-2026:61374CGA-2293-g386-3wj8CGA-23p2-4g53-4jqjCGA-2m5q-8c8r-9jfjCGA-37rv-7cr7-j2qmCGA-39cp-rmc4-8g22CGA-3fpq-q5p9-6qpxCGA-43jw-7f64-g333CGA-4636-mvpp-qwm5CGA-49c3-f38c-28j4CGA-4hx9-93vp-8q6jCGA-4j98-333r-7x38CGA-4qrr-9vcq-x3wwCGA-566x-2h6x-fcj6CGA-5c59-gqwv-5v3wCGA-5hrf-j7ff-2cm2CGA-5xp5-5x2x-x86xCGA-652x-2vrh-cr88CGA-66q3-94vh-jc9pCGA-68hq-r6rr-68m7CGA-6vj7-x4f5-j532CGA-6xc5-466m-m9m9CGA-75v4-m89f-h87mCGA-7994-qwpg-f2jxCGA-7cp9-59xp-xmqgCGA-7pqw-xw9j-56q3CGA-7vgr-c37w-23g9CGA-928g-p6jh-pqchCGA-93cg-7vx2-q22qCGA-95hv-x8gg-prg2CGA-97qp-c68q-8hhhCGA-97rx-fjfg-8h3fCGA-9qfp-m6f8-8rf7CGA-9wm9-frg9-4wmmCGA-9xjh-jmmp-42wqCGA-c3hg-87hh-wqh2CGA-cmp4-p8jr-g4rvCGA-cpfp-rprp-gh8vCGA-cvqq-p3fx-87f5CGA-cx2p-jwqf-m33hCGA-cx8m-jfmj-h39mCGA-cx8m-mp82-q8phCGA-f4x2-667h-xgprCGA-fpxx-v7qp-xjhwCGA-fqqh-fw28-r4mwCGA-g8vg-72pj-5pf8CGA-gc3h-mjm8-9chwCGA-ghmm-85p3-3ggvCGA-gjrj-hgp5-93q5CGA-gvhm-jg5v-6v57CGA-gx9x-j7q4-37v2CGA-h4gr-mgg2-4c6pCGA-hh7c-8wxc-m668CGA-hhqq-c5c8-wr6gCGA-m2m9-7q8p-pjh2CGA-m9mg-xjcp-5jvcCGA-m9qc-3847-5x82CGA-m9qg-cqw7-p3f6CGA-mrg2-rr44-hx45CGA-mxp4-935x-xv47CGA-pq7q-2rp2-4fmwCGA-pqvr-jjxp-vmcqCGA-235w-3776-2h2gCGA-23j2-h2wq-9ph4CGA-25rv-fhw8-92wrCGA-268r-76mg-qpq9CGA-2ggm-m8gq-whggCGA-2jvf-923j-4r69CGA-2q5v-8262-6mr6CGA-2r4q-wcj9-763xCGA-2v7j-w5rh-rvcgCGA-2w47-jmpp-j897CGA-3827-fgqx-9p64CGA-3c5g-f5jp-5gg6CGA-3cw5-f3gh-g4f9CGA-3q59-gxg9-jc9vCGA-3q6x-5p2v-hgfxCGA-3r7q-g687-2x28CGA-3rm7-m5c9-333qCGA-3w29-gmg9-cvhgCGA-3w4m-m59f-4fcjCGA-444c-r4x2-v98wCGA-454q-p93m-x5fwCGA-47pc-jfv3-rf2gCGA-485j-52gm-67wpCGA-48p3-vg5h-m65rCGA-4c7w-hp63-3f5qCGA-4pq3-hmrx-j46mCGA-4pq8-m4hf-qv7xCGA-4xvj-3m5r-hv84CGA-5485-2m6q-g7r3CGA-5cmf-wjh9-hpr9CGA-5gqp-p333-7cpwCGA-5hv9-q2gm-f9qwCGA-5ppv-96qx-qxxxCGA-5wqg-2qwm-g3whCGA-65ff-6p52-pj9xCGA-66mc-f5fg-25vpCGA-67cg-gpm3-frh9CGA-693w-2654-7qppCGA-69wq-679r-wvvrCGA-6c5v-cmfv-h48xCGA-6c93-83wr-3mvvCGA-6mj8-w2w8-5gr8CGA-6qjc-635m-5mq2CGA-6wj5-whg5-75fpCGA-74q7-qw7v-7mx9CGA-78rc-h6ff-fm9xCGA-7943-95rj-gpjvCGA-79w7-w6wh-hcg7CGA-7cm9-9367-w374CGA-7jj7-fcg3-q6r3CGA-7mp2-m7xj-3m3wCGA-7pxf-47f4-3v62CGA-7vcf-3g5g-c5chCGA-7w89-vhx4-j7m9CGA-8694-mwx6-w439CGA-8cgv-92j5-x4w7CGA-8cxw-9cxg-2c4fCGA-8hwv-rr7x-j5fjCGA-8m2h-gh5h-gfw8CGA-8q37-x5xh-w6cvCGA-9478-hvf7-g39wCGA-95g4-r2jr-jw6wCGA-9652-x2wq-66v3CGA-97gx-9r8g-p66xCGA-99wg-3gh7-p4g9CGA-9fvr-gpv8-qgw6CGA-9hm2-f248-8rpvCGA-9qqc-8h3m-w3q9CGA-9qx9-x792-x78fCGA-9whx-q8j2-6x63CGA-c2jg-jq78-fxpqCGA-c7rh-c638-w95hCGA-cf74-5ww8-m8m3CGA-cmp2-q246-f9cgCGA-cmxj-8h87-f3hfCGA-cp93-6q5j-6h2cCGA-cqpg-4g6p-7fccCGA-cqrh-f268-c74jCGA-cwqq-qxx8-fgr8CGA-f24p-95hf-xmf5CGA-f3h7-r65w-qfrxCGA-f5p5-r68f-w897CGA-f5r6-h7f8-mcjfCGA-f5w6-hcrm-vx48CGA-f7g4-4876-g822CGA-f8cf-x36m-p5gwCGA-fh5x-hfj6-grprCGA-fhg9-4j62-w8mxCGA-fhr7-6vxh-p824CGA-fvqw-2c79-h5g3CGA-fwx6-g9w9-6g9pCGA-g46p-f7w9-fwm7CGA-g5h4-fhhg-9cp3CGA-gcm9-mqhf-w55qCGA-gcr4-8fp9-3g73CGA-gg5h-hghq-5pr6CGA-gh59-m36v-f3x7CGA-gj4f-wm7p-j6vrCGA-gm9p-992m-vpjfCGA-gqq5-wg86-j995CGA-gr7v-9cpx-qj2mCGA-grc2-c9fj-m7hpCGA-gw42-6fm4-7x84CGA-gw6v-x7x6-23ghCGA-gwxm-4pmj-q7x3CGA-gx46-388m-4g94CGA-gxg4-9v84-x564CGA-h3cm-8f9j-jpffCGA-h3fc-rjp7-g2pmCGA-h4f4-5cfw-hc4xCGA-h5p9-3h9p-9g4qCGA-h92m-6gpq-mfvgCGA-hmvg-5642-96vrCGA-hqcw-wqxw-jgj9CGA-hqpj-86vg-446qCGA-hrr4-qp5w-f965CGA-hv55-vmw5-xxfrCGA-hxjw-3v2h-2h48CGA-j28x-4gqq-xr77CGA-j326-pmxg-98qxCGA-j3xv-64f3-27v7CGA-j5w9-367c-j4qmCGA-j757-43rq-vr2pCGA-jc2r-85xp-gm2pCGA-jfhp-3r52-prphCGA-jpwc-q433-hr4mCGA-jx5p-5ggj-cwpxCGA-m5f3-mq72-894jCGA-m723-xq6g-x76jCGA-m76c-jrvc-x33fCGA-m7fr-484v-fqqcCGA-mj63-8r26-74xwCGA-mjgj-x3jm-wp66CGA-mp75-gpx9-hjccCGA-mpr2-84f9-wm3jCGA-mv5j-2v79-g7hvCGA-mwq3-p3rv-fr9gCGA-mxrr-9pjj-gfr7CGA-p2c8-rc6v-7rfgCGA-p5h2-4gqc-9j9xCGA-p9jx-r9qg-9m2cCGA-prgx-p2rm-x7rrCGA-pvgw-mgq9-m6vcCGA-q296-fj6g-v787CGA-q2q8-qvjv-xxw5CGA-q2v8-4g8c-qg9wCGA-q35j-w4m7-55c4CGA-q4mp-7v3v-j85cCGA-q9c4-2g8h-qcpgCGA-qfp7-jchf-8779CGA-qm72-9wh5-w6g6CGA-qm95-5395-m55qCGA-qp5m-4p49-3p56CGA-qp85-rvg9-qj7jCGA-qqq2-fcvh-p8p9CGA-qr69-h54f-8pq9CGA-qwfj-332m-5jxcCGA-qwh8-cxvm-c64mCGA-qwjq-h3h8-27rxCGA-r3g8-3m54-j9qjCGA-r4w8-j37m-w9jpCGA-r558-6743-jvgrCGA-r5m2-55xc-c6hfCGA-r66c-vmp3-3wfcCGA-r8fw-5j8x-5g72CGA-rc37-3ffv-mhw2CGA-rfxv-8m5c-rp8jCGA-rhrf-hvw3-pjj3CGA-rpwf-j82c-74vjCGA-rq83-v34r-gjg2CGA-rqm3-hp2c-5fvpCGA-rqpr-rrh3-xm97CGA-v4h5-8qv8-h99pCGA-v6pm-cwhv-jxjjCGA-v845-2gm3-pj4xCGA-v8xm-9rv9-xjpqCGA-vc2w-5mv2-f4c2CGA-vqqr-m6jw-5h8cCGA-vwh6-jvv5-8vrfCGA-vwm2-3j89-4pj8CGA-w37p-p9x7-v696CGA-w67f-qv27-mvv4CGA-w9h4-rhrc-3v7gCGA-wfj5-p9qh-hxfhCGA-wfx8-p2vh-h637CGA-wgj9-ph4w-6mhfCGA-wh7h-4pv7-q33fCGA-wmxv-66qw-wgv3CGA-wmxv-822c-v4c2CGA-wr39-3qjg-v5h9CGA-wr5q-994r-cfvcCGA-wvg8-86q9-wpv8CGA-wvgg-cx23-hhp6CGA-wx8f-7wv8-7wxjCGA-x35g-vqpx-4q73CGA-x3ch-r7p7-q694CGA-x649-j89j-x4m6CGA-x9hx-5qv6-9xcrCGA-xc2g-xgqq-4p4vCGA-xcxx-c7m2-g4c4CGA-xjmx-p773-xv45CGA-xp3j-fgvr-2pj9CGA-xq9v-4h2c-p2frCGA-xqmr-vx4p-5f9jCGA-xr62-mpvc-24mpCGA-xv6v-325c-7c2vCGA-xvpm-9577-f25hCGA-xx9q-3pqf-pxfvCGA-39xv-6h5f-2vm2CGA-5jmg-wq65-hfm8CGA-7cc9-6297-q4ffCGA-mw62-435f-f536CGA-mrqq-87hf-vg32CGA-pqmp-57g7-p223CGA-5p74-x8q7-3v98CGA-6pwg-cf4x-cvhqCGA-8m58-4r6p-j6jfCGA-jw2w-q9cc-5w7gCGA-7vh6-72cq-r6xhCGA-gxp4-m8g8-w88gCGA-r8cx-gm5c-wg94
Advisory lineage Upstream: 0 Downstream: 14
Analyzed
Published: 03 Aug 2026, 16:33
Last modified:03 Aug 2026, 20:12

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.62% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Aug 2026, 16:33
Published
Vulnerability first disclosed
03 Aug 2026, 20:12
Last Modified
Vulnerability information updated

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.62% Percentile: 48%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardactions-runner

    < 2.336.0-r4

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.12

    < 3.12.9.4-r15

  • chainguardargo-workflows-ui-3.6

    all

  • chainguardargo-workflows-ui-3.7

    < 3.7.17-r1

  • chainguardargo-workflows-ui-4.0

    < 4.0.8-r2 | < 4.0.11-r0

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.5

    < 2026.5.6-r3

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r3

  • chainguardazurite

    < 3.35.0-r2

  • chainguardbash-language-server

    < 5.6.0-r4

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddotstatsuite-supercore

    < 3.1.0_git20260803-r1

  • chainguardfoxx-cli

    < 2.1.1-r10

  • chainguardgemini-cli

    < 0.49.0-r7

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.8-r1

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardgraalvm-25-ce-nodejs

    < 25.0.4-r15

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r40

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.0-r2

  • chainguardlangfuse-4-worker

    < 4.3.1-r1

Showing first 50 affected entries in server-rendered view.

References (22)