Bug 2494813 (CVE-2026-13149)
| Summary: | CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aadhikar, aazores, abarbaro, abrianik, abuckta, akhatavk, akostadi, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aos-team-art-private, aruklets, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bdettelb, bmaxwell, boliveir, bparees, brasmith, bsmejkal, bstansbe, cdrage, chfoley, cmah, cochase, csuconic, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dlofthou, dmayorov, doconnor, dpaolell, dranck, drichtar, drow, dschmidt, dymurray, eaguilar, ebaron, ehelms, ehugonne, ewittman, fdeutsch, fmariani, gbenhaim, ggainey, ggrzybek, gmalinko, gparvin, gtully, hasun, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jbalunas, jburrell, jchui, jdelft, jfula, jhe, jkoehler, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jraez, jreimann, jsherman, jtolenti, jturenov, jupierce, juwatts, jweiser, jwon, kaycoth, kshier, ktsao, kvanderr, lchilton, lgarciaa, lphiri, lryznaro, manissin, mbiarnes, mcarlett, mdellweg, mdessi, mhulan, mosmerov, mposolda, mreynolds, mrizzi, msauton, mstipich, msvehla, nboldt, nipatil, niyer, nmoumoul, nwallace, nyancey, oaljalju, ometelka, orabin, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, ppalepu, ppostler, prdhamdh, progier, psrna, ptisnovs, rchan, rekumar, rexwhite, rgemmell, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, smullick, snegrini, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, stirabos, suppawar, swoodman, syedriko, tasato, tbish, tbordaz, tcunning, teagle, thason, thjenkin, tlavocat, tmalecek, tsedmik, tsze, twaugh, vashirov, vdosoudi, vkumar, vlaad, vmuzikar, vvoronko, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-08-05 11:14:39 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2494949, 2494950, 2494951, 2494952, 2494953, 2494954, 2494955, 2494956, 2494957, 2494958, 2494961, 2494962, 2494964, 2494965, 2494967, 2494968, 2494969, 2494970, 2494972, 2494976, 2494977, 2494944, 2494945, 2494946, 2494947, 2494948, 2494959, 2494960, 2494963, 2494966, 2494971, 2494973, 2494974, 2494975, 2494978, 2494979 | ||
| Bug Blocks: | |||
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47060 https://access.redhat.com/errata/RHSA-2026:47060 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47059 https://access.redhat.com/errata/RHSA-2026:47059 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47057 https://access.redhat.com/errata/RHSA-2026:47057 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47058 https://access.redhat.com/errata/RHSA-2026:47058 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48032 https://access.redhat.com/errata/RHSA-2026:48032 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48034 https://access.redhat.com/errata/RHSA-2026:48034 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48033 https://access.redhat.com/errata/RHSA-2026:48033 This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:52394 https://access.redhat.com/errata/RHSA-2026:52394 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:52399 https://access.redhat.com/errata/RHSA-2026:52399 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:53298 https://access.redhat.com/errata/RHSA-2026:53298 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590 This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.1 Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488 This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.6 Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545 |
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.