Description
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The braces library (v3.0.3) contains a stack overflow caused by recursive abstract syntax tree walkers that lack depth guarding. An attacker can craft deeply nested brace patterns within the allowed character limit. When the parser processes these patterns, the unbounded recursion exhausts the Node.js call stack and throws an uncaught RangeError, terminating the Node.js process and resulting in a denial‑of‑service condition.

Affected Systems

Any Node.js application that imports or depends on micromatch braces version 3.0.3 is affected, as the library's recursive walkers are used during pattern compilation.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity, while the EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers only need to supply a malicious pattern to trigger the stack overflow; the vector is likely local or remote through user-supplied input to the braces parser, and the exploitation does not require elevated privileges.

Generated by OpenCVE AI on September 23, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade micromatch braces to a version newer than 3.0.3 that implements depth guards for its recursive walkers.
  • Add input validation to limit the nesting depth of brace patterns before they reach the library, preventing recursion from exceeding a safe threshold.
  • If an upgrade is not possible in the short term, sanitize or reject user‑supplied patterns that approach the maximum nesting depth or replace braces processing with a safer alternative.

Generated by OpenCVE AI on September 23, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vfj7-8cjw-p6xm braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Micromatch
Micromatch braces
Vendors & Products Micromatch
Micromatch braces

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
Title braces through 3.0.3 Stack Overflow via Deeply Nested Patterns
First Time appeared Jonschlinkert
Jonschlinkert braces
Weaknesses CWE-674
CPEs cpe:2.3:a:jonschlinkert:braces:*:*:*:*:*:node.js:*:*
Vendors & Products Jonschlinkert
Jonschlinkert braces
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Jonschlinkert Braces
Micromatch Braces
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:04.389Z

Reserved: 2026-09-18T14:39:01.117Z

Link: CVE-2026-93687

cve-icon Vulnrichment

Updated: 2026-09-18T16:56:38.072Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:15.507

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93687

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T15:06:02Z

Links: CVE-2026-93687 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:15:17Z

Weaknesses
  • CWE-674

    Uncontrolled Recursion

  • CWE-770

    Allocation of Resources Without Limits or Throttling