Back

HIGH

brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion

Published Sep 28, 2026

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 28, 2026
Updated Oct 1, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Important
Public date Sep 28, 2026
GHSA-QHR7-859C-M2P7