Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Denial of Service in nodejs-nodemon (Red Hat)

Дата публикации: 30-07-2026 16:08:36



Основное содержимое страницы с новостью.

Sicherheit: Denial of Service in nodejs-nodemon

Aktuelle Meldungen Distributionen

Name: Denial of Service in nodejs-nodemon
ID: RHSA-2026:48032
Distribution: Red Hat
Plattformen: Red Hat Enterprise Linux AppStream (v. 10)
Datum: Do, 30. Juli 2026, 18:09
Referenzen: https://access.redhat.com/security/cve/CVE-2026-13149
https://bugzilla.redhat.com/show_bug.cgi?id=2494813
https://access.redhat.com/errata/RHSA-2026:48032
Applikationen: nodejs-nodemon

Originalnachricht

An update for nodejs-nodemon is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Simple monitor script for use during development of a node.js app. For use
during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script.

Security Fix(es):

* brace-expansion: Brace-expansion: Denial of Service due to exponential-time
complexity (CVE-2026-13149)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2026-13149: Inefficient Regular Expression Complexity (CWE-1333)

Pro-Linux @Facebook

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Denial of Service in fence-agents (Red Hat)024.2930-07-2026
2Denial of Service in dovecot (Red Hat)0520-07-2026
3Denial of Service in freeipmi (Red Hat)-5708-07-2026
4Denial of Service in freeipmi (Red Hat)0508-07-2026
5Denial of Service in rsyslog (SUSE)01030-07-2026
6Mehrere Probleme in nodejs24 (Red Hat)01030-07-2026
7Denial of Service in openssl-3 (SUSE)01030-07-2026
8Denial of Service in openssl-3 (SUSE)01030-07-2026
9Denial of Service in apache-commons-lang3, google-guice, maven-resolver, xmvn und maven (SUSE)037.2730-07-2026
10Mehrere Probleme in nginx (SUSE)01030-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 24.29. Источник: www.pro-linux.de.