CVE-2026-102276 Details
Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.
A denial-of-service vulnerability has been identified in the brace-expansion library, specifically in versions prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10. The issue arises in the 'parseCommaParts' function, which processes brace patterns recursively. This recursion can be exploited by crafting patterns with numerous comma-separated brace groups, causing the function to exhaust the native stack and crash the Node.js process. Additionally, the vulnerability can be triggered by using 'push.apply' to pass a large array of comma parts, bypassing the recursion but still leading to a stack overflow. The vulnerability occurs before any output is generated, allowing it to evade existing length checks. As a result, applications that use the brace-expansion library to process user-supplied input can be vulnerable to remote, unauthenticated denial-of-service attacks.
Users can upgrade to brace-expansion versions 1.1.19, 2.1.5, 3.0.7, or 5.0.10 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juliangruber brace-expansion | < 1.1.19 (semver) >= 2.0.0, < 2.1.5 (semver) >= 3.0.0, < 3.0.7 (semver) >= 4.0.0, < 5.0.10 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion