PT-2026-95431 · Npm · Braces

·

CVE-2026-93687

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions braces versions prior to 3.0.4
Description A stack overflow occurs in the recursive AST (Abstract Syntax Tree) walkers due to a lack of depth guards. An attacker can provide deeply nested brace patterns that remain within the character limit to exhaust the call stack, resulting in the termination of the Node.js process via an uncaught RangeError.
Recommendations Update braces to version 3.0.4 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103445
AZL-103481
CVE-2026-93687

Affected Products

Braces