Back

HIGH

brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion

Published Sep 28, 2026

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 28, 2026
Updated Sep 29, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Important
Public date Sep 28, 2026
GHSA-6J4F-FJ2G-MC7P