Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.
Published: 2026-09-28
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via stack exhaustion
Action: Apply Patch
AI Analysis

Impact

The brace‑expansion library processes strings with brace syntax to generate many combinations. Prior to specific releases, a pattern with deeply nested braces causes the library to recurse once for each level of nesting when expanding comma‑separated members or single set members. The uncontrolled recursion exhausts the native stack before any output limits are reached, terminating the Node.js process and resulting in a denial of service. This flaw is directly tied to resource exhaustion (CWE‑400) and improper recursion control (CWE‑674). The impact is primarily availability, as a rogue input can force the application to crash or become unresponsive. The CVSS score of 7.5 indicates a medium‑to‑high severity vulnerability.

Affected Systems

The vulnerability affects the brace‑expansion package maintained by juliangruber. Versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11 are vulnerable. Any Node.js application that imports this library and accepts untrusted input containing brace syntax, such as command‑line utilities, build tools, or web services, may be exposed.

Risk and Exploitability

An attacker can supply a crafted pattern with many nested braces to the library. Because the library performs uncontrolled recursion, the attack requires only a legitimate call to the expand function with malicious input; no special privileges or credentials are needed. The lack of an EPSS score and absence from the KEV catalog suggest that this vulnerability has not yet been widely exploited, but the medium‑high CVSS rating and the straightforward attack vector elevate the risk for deployments that rely on user‑provided brace expressions.

Generated by OpenCVE AI on September 28, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade brace‑expansion to 1.1.20 or later, 2.1.6 or later, 3.0.8 or later, or 5.0.11 or later.
  • Validate or sanitize input patterns before passing them to expand, rejecting patterns that exceed a safe nesting depth or length.
  • Implement process monitoring and automatic restart or alarm mechanisms to detect and recover from unexpected Node.js termination.

Generated by OpenCVE AI on September 28, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.
Title brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
Weaknesses CWE-400
CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T20:57:09.850Z

Reserved: 2026-09-28T20:11:16.659Z

Link: CVE-2026-102278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T21:17:16.517

Modified: 2026-09-28T21:17:16.517

Link: CVE-2026-102278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T22:30:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-674

    Uncontrolled Recursion