medium · CVSS v3 5.3
CVE-2026-102277
The brace-expansion library in Node.js can be triggered to consume excessive CPU and memory when processing malformed patterns with many tra
Overview
The brace-expansion library in Node.js can be triggered to consume excessive CPU and memory when processing malformed patterns with many trailing braces. This causes a temporary denial of service by blocking the event loop, but the process eventually recovers. It affects any Node.js application that imports the library before the patched versions.
Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
Impact
The vulnerability leads to a denial of service, impacting the availability of Node.js applications. Developers, system administrators, and end users may experience temporary service interruptions. Confidentiality and integrity remain unaffected.
Remediation
Upgrade the brace-expansion package to version 1.1.21 or later, 2.1.7 or later, 3.0.9 or later, or 5.0.12 or later. If an upgrade is not immediately possible, implement input validation to reject patterns with excessive closing braces and enforce CPU/memory limits on Node.js processes.
Risk context
The CVSS v3 score is 5.3 (medium). No EPSS data is available. The issue is recoverable but can impact availability during high-load scenarios.
Affected products
- brace-expansion
- Node.js
- npm
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —