Repository navigation
chore(deps): update dependency brace-expansion@<1.1.13 to v5 [security] - #267
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
2 times, most recently
from
October 5, 2026 17:35
3d5b2ff to
7d29702
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
October 5, 2026 22:44
7d29702 to
48b2d2b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.1.18→^5.0.12brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p
More information
Details
Summary
parseCommaParts()can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string.This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made
expand_()iterative and documented a constant-stack-depth guarantee, butparseCommaParts()was left recursive, so the guarantee only held for one of the two parsing paths.Vector 1 - unbounded recursion on
postparseCommaParts()recursed on the remainder of the string once per brace group:A brace group containing many comma-separated groups drives one recursion level per group:
About 7,300 repetitions - roughly 29 KB of input - is enough on Node 24; roughly 6,300 (25 KB) on Node 18. The threshold is identical on every affected release line.
Vector 2 -
push.applywith an unbounded arrayEven with the recursion removed,
parseCommaParts()spread whole arrays into an argument list:Function.prototype.applyplaces one argument per element on the stack, so a single large array overflows it. This needs no recursion depth at all - the following reaches a recursion depth of exactly 1:Threshold is about 124,300 repetitions (~249 KB). This vector was not part of the original report; it was found while verifying the fix. A patch that only de-recurses but keeps
push.applyleaves a working denial of service behind.Why
maxandmaxLengthdo not helpBoth crashes happen during parsing, before any expansion. The payloads produce one result per group, so output size grows linearly with input and is never the limiter.
expand(payload, { max: 1, maxLength: 1 })still overflows.Impact
Any application that passes an untrusted string to
expand()- directly, or throughminimatch/globwhere it is a user-supplied glob pattern - can be crashed. In Node, aRangeErrorthat the application does not catch terminates the process, so a server that globs user input is exposed to remote unauthenticated denial of service.minimatch's ownMAX_PATTERN_LENGTHcap (65,536) does not help against vector 1: the overflow threshold sits well below it. Confirmed on minimatch 10.2.6 - a 64,003-byte pattern passes the length check and overflows bothminimatch.braceExpand()andnew minimatch.Minimatch().This is an availability-only issue. No code execution and no data exposure.
Not a regression
5.0.8 and 5.0.9 overflow at the same repetition count, so the gap predates the recent advisories; those fixes simply did not reach it. Verified affected on 1.1.18, 2.1.4, 3.0.6, 5.0.8 and 5.0.9, all at an identical threshold.
Patch
parseCommaParts()is rewritten as a loop that carries the partial part across chunks, and every array append uses an element-by-element loop rather thanpush.apply. The redundantif (!str) return ['']guard is dropped - the loop returns['']for the empty string on its own.Equivalence of the old and new implementations was checked by differential testing: exhaustive over every string of
{,},,,aup to length 7 plus 300,000 random inputs - 322,000 cases, zero mismatches.Severity note
Scored 7.5 High under CVSS 3.1 for consistency with the other availability advisories on this package (GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895), which use the same vector. The reporter self-assessed 6.9 Medium under CVSS 4.0 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N).Credit
Reported by baeseungwon1010, with a working proof of concept and a proposed patch. Vector 2 was identified during maintainer verification.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
CVE-2026-102278 / GHSA-qhr7-859c-m2p7
More information
Details
Summary
expand_()recurses once per level of brace nesting. Deeply nested input exhausts the native stack and crashes the process.This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the tail iterative (recursion on
m.post, driven by how many groups are chained). Nesting depth drives a different recursion that the tail fix never touched, so the documented constant-stack-depth guarantee only ever covered chained input, not nested input.It is also distinct from GHSA-6j4f-fj2g-mc7p, which fixed recursion in
parseCommaParts(). Both payloads below still crash with that fix applied.Two recursion sites
Comma members. Each alternative of a brace set is expanded by a recursive call, so nesting a set inside every alternative recurses once per level:
Crashes at depth 3,907 - about 15.6 KB of input.
Single set. A brace set whose body parses to a single part is expanded by a recursive call before being re-wrapped (
x{{a,b}}y->x{a}y x{b}y), which recurses once per nesting level:Crashes at depth 3,125 - about 6.25 KB of input. This is the cheapest stack-exhaustion payload known against this package: roughly a quarter the input of GHSA-6j4f-fj2g-mc7p (29 KB), and about a tenth of minimatch's
MAX_PATTERN_LENGTH(65,536).Why
maxandmaxLengthdo not helpBoth crashes happen while recursing into sub-expansions, before the result set grows. The payloads produce almost no output - the single-set case yields 2 results - so neither bound is ever the limiter.
expand(payload, { max: 1, maxLength: 1 })still overflows.Impact
Any application passing an untrusted string to
expand(), directly or throughminimatch/globas a user-supplied glob pattern, can be crashed. In Node aRangeErrorthe application does not catch terminates the process, so a server globbing user input is exposed to remote unauthenticated denial of service.Availability only. No code execution, no data exposure.
Affected versions
Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, at near-identical depths on every line (single set: 3,125 on all four; comma members: 3,907-4,102). Not a regression from any recent fix - the gap predates them.
Patch
A
maxDepthbound (defaultEXPANSION_MAX_DEPTH) is threaded throughexpand_(). Past the cap a group is treated as non-expanding and returned literally, which is how the parser already handles a group that cannot expand. This matches the existingmax/maxLengthcaps, which truncate rather than throw, soexpand()continues never to throw on any input.The default sits far above any realistic nesting depth and well below the crash threshold.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
brace-expansion: Quadratic-time expansion of the
{a},b}rewrite causes CPU denial of serviceCVE-2026-102277 / GHSA-q2hr-2g5m-vwhr
More information
Details
Summary
Expanding
{a},b}-shaped input takes time quadratic in the number of literal}characters, blocking the event loop.Bash preserves a quirk where a brace group followed by a comma set still expands (
{a},b}). The parser implements this by rewriting the string and restarting the scan. Each pass absorbs exactly one}and re-scans from the beginning, sontrailing braces costnfull passes.Reproduction
ms/n^2is flat at ~1.7 and each doubling ofncosts exactly 4.0x - quadratic. 128 KB of input blocks the event loop for nearly half a minute to produce two results.Mechanism
Instrumenting the rewrite branch confirms it runs exactly
n + 1times, once per literal}, each re-scanning the whole string.There is a second multiplier. The rewrite replaces the group's closing
}with the internalescClosesentinel, which is'\0CLOSE' + Math.random() + '\0'- about 25 characters. The working string therefore grows by ~25 characters on every pass:So the input is inflated roughly 26x, and that factor multiplies both the quadratic constant and peak memory. This makes it partly a memory-pressure issue as well as a CPU one.
Why
maxandmaxLengthdo not helpThe cost is in parsing, before the result set exists. The payload yields 2 results regardless of size, so neither bound is ever reached.
Impact
An application passing an untrusted pattern to
expand(), directly or throughminimatch/glob, can have its event loop blocked for tens of seconds by a payload well under minimatch's 65,536-character cap. For a single-threaded Node server that is a full stall, not just a slow request.Degraded availability rather than a crash - the process recovers once the expansion completes.
Affected versions
Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, all within a few percent of each other (~460-490 ms at n=16,000).
Patch
The rewrite loop gets an iteration bound. Past the cap the remaining string is treated as non-expanding and returned literally, consistent with the existing
max/maxLengthcaps, which truncate rather than throw.Note this bounds the number of passes, not the cost of each: worst-case work remains proportional to
cap x input length. The cap is set low enough that the residual is bounded in practice, and far above what any realistic{a},b}input needs.Severity note
Scored 5.3 Medium (
A:L) for consistency with GHSA-3jxr-9vmj-r5cp, the other algorithmic-complexity advisory on this package (CWE-407), which uses the same vector. The stack-exhaustion advisories on this package scoreA:Hbecause they crash the process outright; this one stalls it.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion@<1.1.13)
v5.0.12Compare Source
v5.0.11Compare Source
v5.0.10Compare Source
v5.0.9Compare Source
v5.0.8Compare Source
v5.0.7Compare Source
v5.0.6Compare Source
v5.0.5Compare Source
v5.0.4Compare Source
v5.0.3Compare Source
v5.0.2Compare Source
v4.0.1Compare Source
5a5cc170b6a978v4.0.0Compare Source
278132bdd72a59tea.yaml70e4c1bAs a precaution to not risk breaking anything with
278132b, this is a new semver major releasev3.0.9Compare Source
v3.0.8Compare Source
v3.0.7Compare Source
v3.0.6Compare Source
v3.0.5Compare Source
v3.0.4Compare Source
v3.0.3Compare Source
v3.0.2Compare Source
v3.0.1Compare Source
3059c078229e6f15f9b3cv3.0.0Compare Source
c0360e868c0e379e781e93494c4ddd5a4cb6dad209teste3dd8aed23ede91eb3fa41e7c9cd252053761a94f1dc741cf8ee56265c8756a05978a7v2.1.7Compare Source
v2.1.6Compare Source
v2.1.5Compare Source
v2.1.4Compare Source
v2.1.3Compare Source
v2.1.2Compare Source
v2.1.1Compare Source
c3a817cv2.1.0Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
14f1d91ed7780a36603d5v2.0.1Compare Source
v2.0.0Compare Source
v1.1.21Compare Source
v1.1.20Compare Source
v1.1.19Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.