Denial of Service Vulnerability in Brace-Expansion Library for Node.js
CVE-2026-102276

7.5HIGH

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-102276?

The brace-expansion library is vulnerable to denial of service, where specially crafted brace patterns can exploit recursive processing in the parseCommaParts function. This results in native stack exhaustion, potentially terminating the Node.js process. The issue arises when handling large arrays fed into the function through push.apply, causing unmanageable argument length and exceeding stack limits. The vulnerability is addressed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.

Affected Version(s)

brace-expansion >= 4.0.0, < 5.0.10 < 4.0.0, 5.0.10

brace-expansion >= 3.0.0, < 3.0.7 < 3.0.0, 3.0.7

brace-expansion >= 2.0.0, < 2.1.5 < 2.0.0, 2.1.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.