Impact
The brace-expansion library contains a flaw in its parseCommaParts function that, when fed deeply nested or very large brace patterns, triggers uncontrolled recursion and large argument array expansion. This causes the Node.js process’s native call stack to overflow before any limit can be applied, resulting in process termination. The vulnerability is a classic resource exhaustion Denial of Service.
Affected Systems
The vulnerability affects the open‑source brace-expansion library maintained by juliangruber. Versions prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10 are impacted. Any Node.js application that imports this library during runtime could be exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers could trigger the DoS by supplying crafted brace patterns through any interface that passes user input to the library. The impact is local to the host running the Node.js process; there is no remote code execution or privilege escalation threat. If the library is used in a publicly exposed service, the denial of service could affect availability for all users of that service.
OpenCVE Enrichment