Denial of Service Vulnerability in @isaacs/brace-expansion Library
CVE-2026-25547

9.2CRITICAL

Key Information:

Vendor

Isaacs

Vendor
CVE Published:
4 February 2026

What is CVE-2026-25547?

The @isaacs/brace-expansion library, a hybrid CommonJS and ESM TypeScript fork, is susceptible to a denial of service attack due to unbounded brace range expansion. An attacker can exploit this vulnerability by providing patterns with repeated numeric brace ranges, which causes the library to attempt to generate every possible combination. This exponential growth in processing demands can lead to excessive CPU and memory consumption, potentially crashing the Node.js process. This issue has been addressed in version 5.0.1, and users are urged to upgrade to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

brace-expansion < 5.0.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.