brace-expansion
npm10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting brace-expansionpage 1 of 1
- CVE-2017-18077HIGHCVSS 7.5EG 7.5fixed in 1.1.72018-01-27
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
- CVE-2025-5889LOWCVSS 3.1EG 3.1fixed in 2.0.2, 1.1.12, 3.0.1 or 4.0.1, by version range2025-06-09
vulnerable: 4.0.0
A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular e…
- CVE-2026-102276HIGHCVSS 7.5EG 7.5fixed in 5.0.10, 3.0.7, 2.1.5 or 1.1.19, by version range2026-09-28
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recurs…
- CVE-2026-102277MEDIUMCVSS 5.3EG 5.3fixed in 5.0.12, 3.0.9, 2.1.7 or 1.1.21, by version range2026-09-28
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by res…
- CVE-2026-102278HIGHCVSS 7.5EG 7.5fixed in 5.0.11, 3.0.8, 2.1.6 or 1.1.20, by version range2026-09-28
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and sing…
- CVE-2026-13149HIGHCVSS 7.7EG 7.7fixed in 5.0.7, 1.1.16 or 2.1.2, by version range2026-06-30
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(),…
- CVE-2026-14257HIGHCVSS 7.5EG 7.5fixed in 5.0.8, 3.0.3, 2.1.3 or 1.1.17, by version range2026-07-23
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining…
- CVE-2026-33750HIGHCVSS 7.5EG 7.5fixed in 5.0.5, 3.0.2, 2.0.3 or 1.1.13, by version range2026-03-27
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loo…
- CVE-2026-45149HIGHCVSS 7.5EG 7.5fixed in 5.0.62026-05-18
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the seque…
- CVE-2026-69152HIGHCVSS 7.5EG 7.5fixed in 1.1.18, 2.1.4, 3.0.6 or 5.0.9, by version range2026-08-03
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded s…
Check whether brace-expansion is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for brace-expansion CVEs against the assets you own.
Book a Demo →