StackRadar

CVE-2026-45149

High

Advisory

Published 18 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 2
affected packages

brace-expansion: Large numeric range defeats documented `max` DoS protection

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
node-brace-expansiondeb1.1.8-1, 1.1.11-1, 2.0.1+~1.1.0-1, 2.0.1+~1.1.0-2no fix listed6
brace-expansionnpm5.0.3, 5.0.4, 5.0.55.0.652
OSV records
DEBIAN-CVE-2026-45149GHSA-jxxr-4gwj-5jf2UBUNTU-CVE-2026-45149

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
brace-expansion@5.0.4
5.0.6

Open the chart page →

589
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-brace-expansion@1.1.11-1
no fix listed

Open the chart page →

10,902
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
brace-expansion@5.0.4
5.0.6

Open the chart page →

9,556
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
brace-expansion@5.0.5
5.0.6

Open the chart page →

5,535
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
brace-expansion@5.0.4
5.0.6

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
brace-expansion@5.0.5
5.0.6

Open the chart page →

1,787
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
brace-expansion@5.0.4
5.0.6

Open the chart page →

4,305
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
brace-expansion@5.0.5
5.0.6

Open the chart page →

1,616
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
brace-expansion@5.0.4
5.0.6

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-45149.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
brace-expansion@5.0.4
5.0.6

Open the chart page →

5,459

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
brace-expansion@5.0.4
5.0.6
3
requarks/wiki:2:latest68f0d1848261
brace-expansion@5.0.4
5.0.6
2
verdaccio/verdaccio:6.10.209b403888c8f
brace-expansion@5.0.4
5.0.6
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
brace-expansion@5.0.5
5.0.6
2
aaronshaf/dynamodb-admin:latestac41724cd997
brace-expansion@5.0.5
5.0.6
1
activepieces/activepieces:0.90.430c10a04fe3d
brace-expansion@5.0.3
5.0.6
1
alazidis/stornx:1.1.1602d4f7f090c
brace-expansion@5.0.3
5.0.6
1
archivebox/archivebox:0.7.41a5a37331091
brace-expansion@5.0.5
5.0.6
1
budibase/database:2.1.0d90f656261c9
brace-expansion@5.0.4
5.0.6
1
chatwoot/chatwoot:v4.15.167ebc751c171
brace-expansion@5.0.5
5.0.6
1
chocobozzz/peertube:v8.1.5052712130691
brace-expansion@5.0.4
5.0.6
1
directus/directus:12.0.29c8470ea465c
brace-expansion@5.0.5
5.0.6
1
drumsergio/genieacs:1.2.16.028244054e1bf
brace-expansion@5.0.3
5.0.6
1
drumsergio/lynxprompt:2.0.75c6afb6679301
brace-expansion@5.0.5
5.0.6
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
brace-expansion@5.0.4
5.0.6
1
etherpad/etherpad:2.7.2b723fe5f2594
brace-expansion@5.0.4
5.0.6
1
evoapicloud/evolution-api:latest966625532d90
brace-expansion@5.0.4
5.0.6
1
fthomas/scala-steward:latest367afe974b7a
brace-expansion@5.0.4
5.0.6
1
haohanyang/compass-web:0.5.054f2112602ee
brace-expansion@5.0.5
5.0.6
1
joplin/server:latest3f7b852959aa
brace-expansion@5.0.5
5.0.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-brace-expansion@2.0.1+~1.1.0-1
no fix listed
1
library/ghost:6.37.01ef2e532ca4d
brace-expansion@5.0.5
5.0.6
1
library/ghost:6.25.12654b1e90413
brace-expansion@5.0.4
5.0.6
1
library/ghost:6.41.129773d6be407
brace-expansion@5.0.5
5.0.6
1
library/ghost:6.39.0-alpine77196da4b0df
brace-expansion@5.0.5
5.0.6
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
brace-expansion@5.0.4
5.0.6
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
brace-expansion@5.0.4
5.0.6
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-brace-expansion@1.1.11-1
no fix listed
1
n8nio/n8n:2.25.7761374d4eb84
brace-expansion@5.0.4
5.0.6
1
neoskop/ixy:2.1.125152b474f54
brace-expansion@5.0.4
5.0.6
1
nocodb/nocodb:0.301.5d9516f0bf546
brace-expansion@5.0.4
5.0.6
1
openhab/openhab:5.2.1bfd4a60e90da
node-brace-expansion@2.0.1+~1.1.0-2
no fix listed
1
openthread/otbr:latestf307f59f6432
node-brace-expansion@1.1.8-1
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-brace-expansion@1.1.8-1
no fix listed
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
brace-expansion@5.0.4
5.0.6
1
pretix/standalone:2026.7.05df3b7aa852e
brace-expansion@5.0.4
5.0.6
1
rocketadmin/rocketadmin:1.17.710955ef540b9
brace-expansion@5.0.5
5.0.6
1
supabase/storage-api:v1.60.4c8eb9858eafe
brace-expansion@5.0.5
5.0.6
1
supabase/storage-api:latestf6c42a04163d
brace-expansion@5.0.4
5.0.6
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-brace-expansion@1.1.11-1
no fix listed
1
tenureai/tenure:v1.0.285f5b222df9a5
brace-expansion@5.0.5
5.0.6
1
treskon/portrait-ui:DEV-lateste7970783bc8d
brace-expansion@5.0.4
5.0.6
1
veecode/devportalc443520aebf7
brace-expansion@5.0.5
5.0.6
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
brace-expansion@5.0.4
5.0.6
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
brace-expansion@5.0.4
5.0.6
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
brace-expansion@5.0.4
5.0.6
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
brace-expansion@5.0.4
5.0.6
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
brace-expansion@5.0.4
5.0.6
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
brace-expansion@5.0.5
5.0.6
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
brace-expansion@5.0.3
5.0.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.