StackRadar

CVE-2026-14257

High

Advisory

Published 23 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
956
of 17,787 indexed, latest versions
Container images
1,000
deployed by those charts
Fix available
2 of 3
affected packages

brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

Carried by container images the latest versions of 956 of 17,787 indexed charts deploy, on 1,000 images.

Affected packageAffected versionsFixed inImages
brace-expansionnpm1.1.1, 1.1.2, 1.1.4, 1.1.6+19 more1.1.17, 2.1.3, 5.0.81,000
node-brace-expansiondeb1.1.8-1, 1.1.11-1, 2.0.1+~1.1.0-1, 2.0.1+~1.1.0-2no fix listed7
npmapk11.17.0-r012.0.1-r21
OSV records
CGA-6hf9-6j4p-2q3vDEBIAN-CVE-2026-14257GHSA-mh99-v99m-4gvgUBUNTU-CVE-2026-14257
Also known as
CGA-mwqw-7q2r-9q5w

Charts affected

956 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
brace-expansion@1.1.11
1.1.17
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
brace-expansion@2.0.1
2.1.3
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
brace-expansion@1.1.11
1.1.17
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
brace-expansion@1.1.11
1.1.17

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
brace-expansion@1.1.11
1.1.17

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
brace-expansion@1.1.11
1.1.17

Open the chart page →

9,381
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
brace-expansion@1.1.11
1.1.17

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
brace-expansion@1.1.11
1.1.17

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-14257.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
brace-expansion@1.1.11
1.1.17

Open the chart page →

3,118

Container images carrying it

1,000 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cryptexlabs/authf:0.12.11189c07411d7c
brace-expansion@1.1.11
1.1.17
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
brace-expansion@2.0.1
2.1.3
1
cspconsole/report-processor:1.0.279a2d8840bfdf
brace-expansion@2.0.2
2.1.3
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
brace-expansion@5.0.6
5.0.8
1
dacinfomotion/h2p:latest68fa393b472c
brace-expansion@2.0.1
2.1.3
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
brace-expansion@1.1.11
1.1.17
1
daskdev/dask-notebook:1.1.0052630f5ca04
brace-expansion@1.1.11
1.1.17
1
datarhei/restreamer:0.6.4655e12f9eeed
brace-expansion@1.1.11
1.1.17
1
davdiv/musicociel:deva85f99be882c
brace-expansion@2.0.1
2.1.3
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
brace-expansion@1.1.11
1.1.17
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
brace-expansion@1.1.11
1.1.17
1
dbgate/dbgate:7.2.0-alpine287077002446
brace-expansion@2.0.1
2.1.3
1
dbgate/dbgate:7.2.3f2dc7423ea88
brace-expansion@2.0.2
2.1.3
1
decayofmind/hubot:3.3.21e18e92fe694
brace-expansion@1.1.11
1.1.17
1
decisionrules/business-intelligence:latest1135a6d4f09b
brace-expansion@2.0.2
2.1.3
1
defactops/defactops-backend:1.0.2307b663c0092a
brace-expansion@2.0.1
2.1.3
1
denisshav/backend:latest4cc8dc5a4499
brace-expansion@1.1.11
1.1.17
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
brace-expansion@1.1.11
1.1.17
1
devkrishan001/backend:latestf1c3acadeabe
brace-expansion@2.0.1
2.1.3
1
devravinder/node-express-app:1.0.05325a96967b5
brace-expansion@2.0.1
2.1.3
1
devspacecloud/ui:0.3.3deef55ff29a7
brace-expansion@1.1.11
1.1.17
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
brace-expansion@1.1.11
1.1.17
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
brace-expansion@1.1.11
1.1.17
1
directus/directus:12.0.29c8470ea465c
brace-expansion@2.0.3
2.1.3
1
directus/directus:11.1.0e3c8bb975350
brace-expansion@2.0.1
2.1.3
1
diygod/rsshub:latest1d4b508b6357
brace-expansion@5.0.7
5.0.8
1
diygod/rsshub:2025-11-097a6312cac0d5
brace-expansion@2.0.2
2.1.3
1
docmost/docmost:0.95.041c8d777cf23
brace-expansion@2.0.2
2.1.3
1
documenso/documenso:v1.8.17f16a9449f18
brace-expansion@2.0.1
2.1.3
1
drumsergio/genieacs:1.2.16.028244054e1bf
brace-expansion@1.1.13
1.1.17
1
drumsergio/lynxprompt:2.0.75c6afb6679301
brace-expansion@5.0.6
5.0.8
1
drumsergio/pumperly:1.4.885bbc3915e9e
brace-expansion@2.0.2
2.1.3
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
brace-expansion@2.0.1
2.1.3
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
brace-expansion@5.0.7
5.0.8
1
ealen/echo-server:0.6.0359761caae37
brace-expansion@1.1.11
1.1.17
1
eameti/node-app:latestf36642affa86
brace-expansion@1.1.11
1.1.17
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
brace-expansion@5.0.6
5.0.8
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
brace-expansion@2.0.1
2.1.3
1
electerious/ackee:3.2.05e7173fa321c
brace-expansion@1.1.11
1.1.17
1
enketo/enketo-express:3.0.4dcad9c2273f6
brace-expansion@1.1.11
1.1.17
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
brace-expansion@5.0.6
5.0.8
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
brace-expansion@5.0.6
5.0.8
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
brace-expansion@1.1.8
1.1.17
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
brace-expansion@1.1.11
1.1.17
1
etherpad/etherpad:2.7.2b723fe5f2594
brace-expansion@5.0.4
5.0.8
1
ethersphere/bzz-token-service:latest7624f11a72ad
brace-expansion@1.1.11
1.1.17
1
ethersphere/etherproxy:1.0.056029b0985f4
brace-expansion@1.1.11
1.1.17
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
brace-expansion@2.0.1
2.1.3
1
ethersphere/onboarding-faucet:0.3.0513154aab230
brace-expansion@2.0.1
2.1.3
1
ethpandaops/assertoor:latest1efa2fba6711
brace-expansion@5.0.6
5.0.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.