juliangruber has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high). The most common weakness class is CWE-400 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-102278High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix41CVE-2026-102276High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix41CVE-2026-102277Medium· 5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix29
juliangruber vulnerabilities
CVEs affecting juliangruber, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-102278High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and si…
CVE-2026-102277Medium· 5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by r…
CVE-2026-102276High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recu…