PT-2026-102377 · Npm · Brace-Expansion

·

CVE-2026-102278

·

Published

2026-09-28

·

Updated

2026-10-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions brace-expansion versions prior to 1.1.20 brace-expansion versions prior to 2.1.6 brace-expansion versions prior to 3.0.8 brace-expansion versions prior to 5.0.11
Description Deeply nested brace groups supplied as an untrusted pattern can cause the expand () and expand() functions to perform uncontrolled recursion at comma-member and single-set expansion sites. This behavior exhausts the native stack before output limits are applied, leading to a process-terminating denial of service in the Node.js process.
Recommendations Update to version 1.1.20 or later. Update to version 2.1.6 or later. Update to version 3.0.8 or later. Update to version 5.0.11 or later.

Exploit

Fix

DoS

Resource Exhaustion

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102278
GHSA-QHR7-859C-M2P7
OPENSUSE-SU-2026:11967-1

Affected Products

Brace-Expansion