PT-2026-53832 · Npm+1 · Brace-Expansion+1

·

CVE-2026-13149

·

Published

2026-06-30

·

Updated

2026-09-04

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions brace-expansion versions prior to 5.0.7
Description A denial of service issue exists where the expand() function exhibits exponential-time complexity when processing consecutive non-expanding '{}' brace groups. An attacker can provide a crafted string to the expand() function, either directly or transitively, leading to excessive CPU consumption and blocking of the event loop. The max option is ineffective in this scenario because it limits the size of the output rather than the amount of recursion work performed.
Recommendations Update brace-expansion to version 5.0.7 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47057
ALSA-2026:47058
ALSA-2026:47059
ALSA-2026:47060
ALSA-2026:48032
ALSA-2026:48033
ALSA-2026:48034
CLEANSTART-2026-KN24948
CVE-2026-13149
ECHO-AE86-415B-BA40
GHSA-3JXR-9VMJ-R5CP
OPENSUSE-SU-2026:11220-1
OPENSUSE-SU-2026:11452-1
OPENSUSE-SU-2026:11680-1
OPENSUSE-SU-2026:21312-1
OPENSUSE-SU-2026:21448-1
RHSA-2026:33866
RHSA-2026:34478
RHSA-2026:35272
RHSA-2026:45360
RHSA-2026:47057
RHSA-2026:47058
RHSA-2026:47059
RHSA-2026:47060
RHSA-2026:48032
RHSA-2026:48033
RHSA-2026:48034
RHSA-2026:52394
RHSA-2026:52399
RHSA-2026:52990
RHSA-2026:53298
SUSE-SU-2026:3713-1
SUSE-SU-2026:3714-1

Affected Products

Rocky Linux
Brace-Expansion