high · CVSS v3 7.5
CVE-2026-102278
The brace-expansion library in Node.js can exhaust the native stack when processing deeply nested brace patterns, causing the Node.js proces
Overview
The brace-expansion library in Node.js can exhaust the native stack when processing deeply nested brace patterns, causing the Node.js process to terminate. This denial‑of‑service flaw affects versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11. It is a high‑severity vulnerability that can disrupt any application relying on brace expansion.
Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.
Impact
Availability is compromised as the vulnerable process may crash, leading to service interruption. Node.js applications, web servers, CI pipelines, and any tooling that accepts untrusted brace patterns are at risk. The flaw does not directly expose data or modify it, but the resulting downtime can impact business operations.
Remediation
Upgrade the brace-expansion package to the fixed versions (≥1.1.20, ≥2.1.6, ≥3.0.8, ≥5.0.11). If an upgrade is not immediately possible, validate or sanitize brace patterns before passing them to expand(), or replace the library with a safer alternative. Monitor application logs for stack overflow or crash events and apply a temporary input size limit on brace patterns.
Risk context
Severity is high with a CVSS v3 score of 7.5. The lack of an EPSS score suggests the risk is not yet quantified by predictive models, but the high severity indicates a need for prompt remediation.
Affected products
- brace-expansion
- Node.js
- npm brace-expansion
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —