Skip to content

fix: bump brace-expansion overrides to patched versions (1.1.18 / 2.1.4 / 5.0.9) - #238

Merged
madebydavid merged 3 commits into
mainfrom
copilot/fix-brace-expansion-vulnerability
Aug 5, 2026
Merged

fix: bump brace-expansion overrides to patched versions (1.1.18 / 2.1.4 / 5.0.9)#238
madebydavid merged 3 commits into
mainfrom
copilot/fix-brace-expansion-vulnerability

Conversation

Copilot AI commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

brace-expansion@2.1.3 has an incomplete DoS mitigation — the maxLength check in combine() doesn't bound the intermediate arrays built before it runs, allowing a ~25 KB input to OOM-crash the process (uncatchable) or a ~400 KB input to stall the event loop for 2+ minutes. Fixed in 2.1.4.

Changes

  • package.json: bumps the existing overrides entry brace-expansion@2 from 2.1.32.1.4
  • package-lock.json: regenerated; all brace-expansion v2.x installs now resolve to 2.1.4

Reachability

expand() is not called directly in this codebase. Exposure is transitive via minimatch/glob used by dev tooling (Mocha, oclif). Active risk is low, but the OOM variant terminates the process silently, so upgrading is the right call regardless.

Original prompt

This section details the Dependabot vulnerability alert you should resolve

<alert_title>brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</alert_title>
<alert_description>### Summary

The maxLength mitigation added in 5.0.8 for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, so try/catch around expand() does not help.

A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.

Details

maxLength was enforced in combine(), the single place output grows. Two arrays are built before combine() runs, and neither was bounded.

1. Comma alternatives accumulate without a running total (memory exhaustion)

Each alternative in {a,b,c,...} is expanded by its own recursive expand_() call, so each receives a full, independent maxLength allowance. The results were then concatenated into a single values array with no cumulative limit:

values = []
for (let j = 0; j < n.length; j++) {
  values.push.apply(values, expand_(n[j], max, maxLength, false))
}

acc = combine(acc, pre, values, max, maxLength, ...)

With A alternatives, values can reach A * maxLength characters before combine() gets a chance to truncate it. At the default maxLength of 4,000,000 and 400 alternatives, that is well past any default heap.

2. Padded sequences ignore maxLength while generating (CPU exhaustion)

expandSequence() was bounded by max (the result count) but never consulted maxLength. A padded sequence's element width follows the input, so {0...01..100000} with a wide pad generates max elements, each as wide as the input, only for combine() to discard all but a handful.

Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to max * width.

pad width input bytes results kept time (5.0.8) time (patched)
20,000 20 KB 199 ~7.3 s ~20 ms
100,000 100 KB 39 ~32 s ~20 ms
400,000 400 KB 9 ~124 s ~18 ms

Output is byte-identical before and after the fix; only the wasted work is removed.

Proof of concept

Memory exhaustion, against 5.0.8:

import { expand } from 'brace-expansion'

const part = '{' + '0'.repeat(50) + '1..100000}'
const input = '{' + Array(400).fill(part).join(',') + '}'  // ~25 KB

try {
  expand(input)
} catch (e) {
  // never reached - the process is already dead
}
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
Aborted

Event-loop stall, against 5.0.8:

import { expand } from 'brace-expansion'

// ~400 KB input, returns 9 results after roughly two minutes of blocking CPU
expand('{' + '0'.repeat(400_000) + '1..100000}')

Impact

Denial of service. Any application that passes attacker-controlled input to expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled with try/catch.

Applications already on 5.0.8 are affected: the 5.0.8 mitigation does not cover these paths.

Patches

Both intermediate arrays are now bounded as they are built, using the same max and maxLength limits already applied in combine():

  • values tracks a running result count and character length while alternatives are appended, and stops once either bound is reached.
  • expandSequence() accepts maxLength and stops generating once the sequence's own characters reach it.

As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how max already behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.

Workarounds

If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns, or pass an explicitly small max and maxLength.

Note that a small maxLength alone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.

Credits

The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.

The sequence-generation issue was found while verifying that report.</alert_description>

high
GHSA-rgw5-rvv9-x895, CVE-2026-69152
brace-expansion
npm
<vulnerable_versions>2.1.3</vulnerable_versions>
<patched_version>2.1.4</patched_version>
<manife...

Co-authored-by: madebydavid <5401249+madebydavid@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix brace-expansion DoS vulnerability by bounding intermediate arrays fix: bump brace-expansion override to 2.1.4 (GHSA-rgw5-rvv9-x895) Aug 5, 2026
Copilot AI requested a review from madebydavid August 5, 2026 12:49
@madebydavid

Copy link
Copy Markdown
Member

@copilot - can we bump the other overrides for brace-expansion too? i think we have 3 different versions in the overrides because of other packages. I think there should be new releases for each major ver we use

Co-authored-by: madebydavid <5401249+madebydavid@users.noreply.github.com>

Copilot AI commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

@copilot - can we bump the other overrides for brace-expansion too? i think we have 3 different versions in the overrides because of other packages. I think there should be new releases for each major...

Done — bumped all three overrides to their latest patched releases in commit fix: bump all brace-expansion overrides to patched versions:

  • brace-expansion@1: 1.1.171.1.18
  • brace-expansion@2: 2.1.32.1.4
  • brace-expansion@5: 5.0.85.0.9

@madebydavid

Copy link
Copy Markdown
Member

@copilot - choose a better title for the PR

Copilot AI commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

@copilot - choose a better title for the PR

I'm not able to rename the PR title directly through my tooling — you can update it from the PR page. A better title would be:

fix: bump brace-expansion overrides to patched versions (1.1.18 / 2.1.4 / 5.0.9)

Copilot AI requested a review from madebydavid August 5, 2026 12:55
@madebydavid madebydavid changed the title fix: bump brace-expansion override to 2.1.4 (GHSA-rgw5-rvv9-x895) fix: bump brace-expansion overrides to patched versions (1.1.18 / 2.1.4 / 5.0.9) Aug 5, 2026
@madebydavid
madebydavid marked this pull request as ready for review August 5, 2026 12:56
@madebydavid
madebydavid merged commit e08c154 into main Aug 5, 2026
1 check passed
@madebydavid
madebydavid deleted the copilot/fix-brace-expansion-vulnerability branch August 5, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants