Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.
Published: 2026-09-28
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via stack exhaustion
Action: Immediate Patch
AI Analysis

Impact

The brace-expansion library contains a flaw in its parseCommaParts function that, when fed deeply nested or very large brace patterns, triggers uncontrolled recursion and large argument array expansion. This causes the Node.js process’s native call stack to overflow before any limit can be applied, resulting in process termination. The vulnerability is a classic resource exhaustion Denial of Service.

Affected Systems

The vulnerability affects the open‑source brace-expansion library maintained by juliangruber. Versions prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10 are impacted. Any Node.js application that imports this library during runtime could be exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers could trigger the DoS by supplying crafted brace patterns through any interface that passes user input to the library. The impact is local to the host running the Node.js process; there is no remote code execution or privilege escalation threat. If the library is used in a publicly exposed service, the denial of service could affect availability for all users of that service.

Generated by OpenCVE AI on September 28, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade brace-expansion to version 5.0.10 or later (this releases include the bug fix for all affected releases).
  • Verify that package.json and lock files resolve to the fixed version and run npm audit or yarn audit to confirm no vulnerable artifacts remain.
  • If an upgrade cannot be performed immediately, limit or sanitize brace patterns passed to the library, for example by restricting input length or rejecting inputs that contain more than a safe number of comma-separated groups.

Generated by OpenCVE AI on September 28, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.
Title brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
Weaknesses CWE-400
CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T20:50:59.984Z

Reserved: 2026-09-28T20:11:16.658Z

Link: CVE-2026-102276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T21:17:16.033

Modified: 2026-09-28T21:17:16.033

Link: CVE-2026-102276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T22:30:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-674

    Uncontrolled Recursion