CVE-2026-102278 Details
Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.
A denial-of-service vulnerability has been identified in the brace-expansion library, affecting versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11. The issue arises in the 'expand_' function, which handles brace expansion. Deeply nested brace groups can cause the function to recurse excessively, exhausting the native stack and leading to a process crash. This uncontrolled recursion occurs at comma-member and single-set expansion sites, allowing for stack exhaustion before output limits can be applied. As a result, the Node.js process may terminate, causing a process-crashing denial-of-service condition.
Users can upgrade to brace-expansion versions 1.1.20, 2.1.6, 3.0.8, or 5.0.11 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| brace-expansion | < 1.1.20 (semver) >= 2.0.0, < 2.1.6 (semver) >= 3.0.0, < 3.0.8 (semver) >= 4.0.0, < 5.0.11 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion