diff --git a/advisories/github-reviewed/2026/07/GHSA-mh99-v99m-4gvg/GHSA-mh99-v99m-4gvg.json b/advisories/github-reviewed/2026/07/GHSA-mh99-v99m-4gvg/GHSA-mh99-v99m-4gvg.json index 7bd33d93799a8..5cfa09da8c32b 100644 --- a/advisories/github-reviewed/2026/07/GHSA-mh99-v99m-4gvg/GHSA-mh99-v99m-4gvg.json +++ b/advisories/github-reviewed/2026/07/GHSA-mh99-v99m-4gvg/GHSA-mh99-v99m-4gvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh99-v99m-4gvg", - "modified": "2026-07-24T21:53:14Z", + "modified": "2026-07-24T21:53:15Z", "published": "2026-07-24T21:53:14Z", "aliases": [ "CVE-2026-14257" @@ -25,16 +25,54 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.0.0" }, { "fixed": "5.0.8" } ] } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "brace-expansion" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.0.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "brace-expansion" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.3" + } + ] + } ], "database_specific": { - "last_known_affected_version_range": "<= 5.0.7" + "last_known_affected_version_range": "<= 2.1.2" } } ], @@ -47,6 +85,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14257" }, + { + "type": "WEB", + "url": "https://github.com/juliangruber/brace-expansion/pull/130" + }, + { + "type": "WEB", + "url": "https://github.com/juliangruber/brace-expansion/pull/136" + }, { "type": "WEB", "url": "https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5"