rootpwn

high · CVSS v3 7.5

CVE-2026-102278

The brace-expansion library in Node.js can exhaust the native stack when processing deeply nested brace patterns, causing the Node.js proces

Overview

The brace-expansion library in Node.js can exhaust the native stack when processing deeply nested brace patterns, causing the Node.js process to terminate. This denial‑of‑service flaw affects versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11. It is a high‑severity vulnerability that can disrupt any application relying on brace expansion.

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.

Impact

Availability is compromised as the vulnerable process may crash, leading to service interruption. Node.js applications, web servers, CI pipelines, and any tooling that accepts untrusted brace patterns are at risk. The flaw does not directly expose data or modify it, but the resulting downtime can impact business operations.

Remediation

Upgrade the brace-expansion package to the fixed versions (≥1.1.20, ≥2.1.6, ≥3.0.8, ≥5.0.11). If an upgrade is not immediately possible, validate or sanitize brace patterns before passing them to expand(), or replace the library with a safer alternative. Monitor application logs for stack overflow or crash events and apply a temporary input size limit on brace patterns.

Risk context

Severity is high with a CVSS v3 score of 7.5. The lack of an EPSS score suggests the risk is not yet quantified by predictive models, but the high severity indicates a need for prompt remediation.

Affected products

  • brace-expansion
  • Node.js
  • npm brace-expansion

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
—
EPSS
—

DoS StackExhaustion Node.js brace-expansion HighSeverity

← All CVEs