Back

MEDIUM

nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js

Published Mar 30, 2021

Description

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

Affected products

Remediation

Red Hat statement

Red Hat Quay includes braces as a dependency of webpack. Braces is only used at build time, not at runtime, reducing the impact of this vulnerability to low.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 30, 2021
Updated Dec 1, 2025
Reserved Dec 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 19, 2018
GHSA-CWFW-4GQ5-MRQX