StackRadar

CVE-2026-45149

High

Advisory

Published 18 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 2
affected packages

brace-expansion: Large numeric range defeats documented `max` DoS protection

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
node-brace-expansiondeb1.1.8-1, 1.1.11-1, 2.0.1+~1.1.0-1, 2.0.1+~1.1.0-2no fix listed6
brace-expansionnpm5.0.3, 5.0.4, 5.0.55.0.652
OSV records
DEBIAN-CVE-2026-45149GHSA-jxxr-4gwj-5jf2UBUNTU-CVE-2026-45149

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
brace-expansion@5.0.4
5.0.6

Open the chart page →

589
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-brace-expansion@1.1.11-1
no fix listed

Open the chart page →

10,902
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
brace-expansion@5.0.4
5.0.6

Open the chart page →

9,556
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
brace-expansion@5.0.5
5.0.6

Open the chart page →

5,535
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
brace-expansion@5.0.4
5.0.6

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
brace-expansion@5.0.5
5.0.6

Open the chart page →

1,787
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
brace-expansion@5.0.4
5.0.6

Open the chart page →

4,305
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
brace-expansion@5.0.5
5.0.6

Open the chart page →

1,616
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
brace-expansion@5.0.4
5.0.6

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
brace-expansion@5.0.4
5.0.6

Open the chart page →

5,459

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
brace-expansion@5.0.3
5.0.6
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
brace-expansion@5.0.5
5.0.6
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
brace-expansion@5.0.4
5.0.6
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
brace-expansion@5.0.3
5.0.6
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
brace-expansion@5.0.5
5.0.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
brace-expansion@5.0.4
5.0.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
brace-expansion@5.0.4
5.0.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
brace-expansion@5.0.4
5.0.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.