Back

HIGH

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

Published Aug 3, 2026

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

Affected products

Remediation

Red Hat statement

Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue. This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.

Red Hat mitigation

To mitigate this vulnerability, do not pass untrusted input to the expand() function.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 3, 2026
Updated Aug 3, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 3, 2026
NVD
Status Analyzed
Modified Aug 5, 2026
Red Hat
Severity Important
Public date Aug 3, 2026
GHSA-RGW5-RVV9-X895