PT-2026-102375 · Npm · Brace-Expansion

·

CVE-2026-102276

·

Published

2026-09-28

·

Updated

2026-10-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions brace-expansion versions prior to 1.1.19 brace-expansion versions prior to 2.1.5 brace-expansion versions prior to 3.0.7 brace-expansion versions prior to 5.0.10
Description Crafted brace patterns can cause native stack exhaustion within the parseCommaParts() function. This occurs because the function recursively processes the remainder once per brace group and utilizes push.apply to pass elements of a large comma-part array as function arguments. Patterns with numerous comma-separated brace groups or very large arrays can trigger these paths before output limits are reached, potentially leading to a process-terminating denial of service in Node.js.
Recommendations Update to version 1.1.19 or later. Update to version 2.1.5 or later. Update to version 3.0.7 or later. Update to version 5.0.10 or later.

Exploit

Fix

DoS

Resource Exhaustion

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105075
AZL-105096
AZL-105248
CVE-2026-102276
ECHO-5000-011F-5261
GHSA-6J4F-FJ2G-MC7P
OPENSUSE-SU-2026:12062-1

Affected Products

Brace-Expansion