Impact
The brace-expansion library can generate strings with a common prefix and suffix. Prior to version 1.1.21, 2.1.7, 3.0.9 and 5.0.12, the expand function recreates its scan for each trailing closing brace seen in an untrusted pattern such as {a},b}. This quadratic re‑scan and linear growth of the working string forces the Node.js event loop to perform extensive CPU work and consume memory until it recovers, resulting in a recoverable CPU‑denial of service.
Affected Systems
This issue affects the Julia Gruber brace-expansion package, which is widely used in many JavaScript projects via npm. Versions older than 1.1.21, 2.1.7, 3.0.9 and 5.0.12 are vulnerable; those exact release numbers are fixed by the corresponding patch commits.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3 and has no EPSS data available; it is not listed in CISA’s KEV. The primary attack vector is an untrusted user‑supplied brace pattern fed to the expand function, which can be exploited by any code path that processes arbitrary input, such as a web application using the library. Once triggered, the denial of service can be mitigated by eventually recovering, but the high CPU usage and memory pressure can degrade overall system performance.
OpenCVE Enrichment