Denial of Service Vulnerability in Brace-Expansion Library for Node.js
CVE-2026-102276
7.5HIGH
What is CVE-2026-102276?
The brace-expansion library is vulnerable to denial of service, where specially crafted brace patterns can exploit recursive processing in the parseCommaParts function. This results in native stack exhaustion, potentially terminating the Node.js process. The issue arises when handling large arrays fed into the function through push.apply, causing unmanageable argument length and exceeding stack limits. The vulnerability is addressed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.
Affected Version(s)
brace-expansion >= 4.0.0, < 5.0.10 < 4.0.0, 5.0.10
brace-expansion >= 3.0.0, < 3.0.7 < 3.0.0, 3.0.7
brace-expansion >= 2.0.0, < 2.1.5 < 2.0.0, 2.1.5
