PT-2026-95431 · Npm · Braces
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
braces versions prior to 3.0.4
Description
A stack overflow occurs in the recursive AST (Abstract Syntax Tree) walkers due to a lack of depth guards. An attacker can provide deeply nested brace patterns that remain within the character limit to exhaust the call stack, resulting in the termination of the Node.js process via an uncaught RangeError.
Recommendations
Update braces to version 3.0.4 or later.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Braces