Update dependency brace-expansion to v5.0.9 [SECURITY] - #1700
Open
renovate[bot] wants to merge 1 commit into
Open
Update dependency brace-expansion to v5.0.9 [SECURITY]#1700renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Generated by renovateBot
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.0.8→5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69152 / GHSA-rgw5-rvv9-x895
More information
Details
Summary
The
maxLengthmitigation added in5.0.8for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, sotry/catcharoundexpand()does not help.A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.
Details
maxLengthwas enforced incombine(), the single place output grows. Two arrays are built beforecombine()runs, and neither was bounded.1. Comma alternatives accumulate without a running total (memory exhaustion)
Each alternative in
{a,b,c,...}is expanded by its own recursiveexpand_()call, so each receives a full, independentmaxLengthallowance. The results were then concatenated into a singlevaluesarray with no cumulative limit:With
Aalternatives,valuescan reachA * maxLengthcharacters beforecombine()gets a chance to truncate it. At the defaultmaxLengthof 4,000,000 and 400 alternatives, that is well past any default heap.2. Padded sequences ignore
maxLengthwhile generating (CPU exhaustion)expandSequence()was bounded bymax(the result count) but never consultedmaxLength. A padded sequence's element width follows the input, so{0...01..100000}with a wide pad generatesmaxelements, each as wide as the input, only forcombine()to discard all but a handful.Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to
max * width.Output is byte-identical before and after the fix; only the wasted work is removed.
Proof of concept
Memory exhaustion, against
5.0.8:Event-loop stall, against
5.0.8:Impact
Denial of service. Any application that passes attacker-controlled input to
expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled withtry/catch.Applications already on
5.0.8are affected: the5.0.8mitigation does not cover these paths.Patches
Both intermediate arrays are now bounded as they are built, using the same
maxandmaxLengthlimits already applied incombine():valuestracks a running result count and character length while alternatives are appended, and stops once either bound is reached.expandSequence()acceptsmaxLengthand stops generating once the sequence's own characters reach it.As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how
maxalready behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.Workarounds
If upgrading is not immediately possible, avoid passing untrusted input to
expand()or to glob brace patterns, or pass an explicitly smallmaxandmaxLength.Note that a small
maxLengthalone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.Credits
The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.
The sequence-generation issue was found while verifying that report.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion)
v5.0.9Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.