Denial of Service Vulnerability in @isaacs/brace-expansion Library
CVE-2026-25547
What is CVE-2026-25547?
The @isaacs/brace-expansion library, a hybrid CommonJS and ESM TypeScript fork, is susceptible to a denial of service attack due to unbounded brace range expansion. An attacker can exploit this vulnerability by providing patterns with repeated numeric brace ranges, which causes the library to attempt to generate every possible combination. This exponential growth in processing demands can lead to excessive CPU and memory consumption, potentially crashing the Node.js process. This issue has been addressed in version 5.0.1, and users are urged to upgrade to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
brace-expansion < 5.0.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
