Bug 2494813 (CVE-2026-13149)

Summary: CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aadhikar, aazores, abarbaro, abrianik, abuckta, akhatavk, akostadi, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aos-team-art-private, aruklets, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bdettelb, bmaxwell, boliveir, bparees, brasmith, bsmejkal, bstansbe, cdrage, chfoley, cmah, cochase, csuconic, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dlofthou, dmayorov, doconnor, dpaolell, dranck, drichtar, drow, dschmidt, dymurray, eaguilar, ebaron, ehelms, ehugonne, ewittman, fdeutsch, fmariani, gbenhaim, ggainey, ggrzybek, gmalinko, gparvin, gtully, hasun, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jbalunas, jburrell, jchui, jdelft, jfula, jhe, jkoehler, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jraez, jreimann, jsherman, jtolenti, jturenov, jupierce, juwatts, jweiser, jwon, kaycoth, kshier, ktsao, kvanderr, lchilton, lgarciaa, lphiri, lryznaro, manissin, mbiarnes, mcarlett, mdellweg, mdessi, mhulan, mosmerov, mposolda, mreynolds, mrizzi, msauton, mstipich, msvehla, nboldt, nipatil, niyer, nmoumoul, nwallace, nyancey, oaljalju, ometelka, orabin, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, ppalepu, ppostler, prdhamdh, progier, psrna, ptisnovs, rchan, rekumar, rexwhite, rgemmell, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, smullick, snegrini, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, stirabos, suppawar, swoodman, syedriko, tasato, tbish, tbordaz, tcunning, teagle, thason, thjenkin, tlavocat, tmalecek, tsedmik, tsze, twaugh, vashirov, vdosoudi, vkumar, vlaad, vmuzikar, vvoronko, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-05 11:14:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2494949, 2494950, 2494951, 2494952, 2494953, 2494954, 2494955, 2494956, 2494957, 2494958, 2494961, 2494962, 2494964, 2494965, 2494967, 2494968, 2494969, 2494970, 2494972, 2494976, 2494977, 2494944, 2494945, 2494946, 2494947, 2494948, 2494959, 2494960, 2494963, 2494966, 2494971, 2494973, 2494974, 2494975, 2494978, 2494979    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-30 10:01:23 UTC
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.

Comment 3 errata-xmlrpc 2026-07-28 15:41:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47060 https://access.redhat.com/errata/RHSA-2026:47060

Comment 4 errata-xmlrpc 2026-07-28 17:15:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47059 https://access.redhat.com/errata/RHSA-2026:47059

Comment 5 errata-xmlrpc 2026-07-29 00:15:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:47057 https://access.redhat.com/errata/RHSA-2026:47057

Comment 6 errata-xmlrpc 2026-07-29 00:20:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:47058 https://access.redhat.com/errata/RHSA-2026:47058

Comment 7 errata-xmlrpc 2026-07-29 17:27:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48032 https://access.redhat.com/errata/RHSA-2026:48032

Comment 8 errata-xmlrpc 2026-07-29 17:52:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48034 https://access.redhat.com/errata/RHSA-2026:48034

Comment 9 errata-xmlrpc 2026-07-29 17:53:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48033 https://access.redhat.com/errata/RHSA-2026:48033

Comment 10 errata-xmlrpc 2026-07-29 19:53:39 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151

Comment 13 errata-xmlrpc 2026-08-10 01:33:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:52394 https://access.redhat.com/errata/RHSA-2026:52394

Comment 14 errata-xmlrpc 2026-08-10 02:41:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:52399 https://access.redhat.com/errata/RHSA-2026:52399

Comment 15 errata-xmlrpc 2026-08-11 06:37:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:53298 https://access.redhat.com/errata/RHSA-2026:53298

Comment 16 errata-xmlrpc 2026-08-20 16:07:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590

Comment 17 errata-xmlrpc 2026-09-10 16:36:56 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.14.1

Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488

Comment 18 errata-xmlrpc 2026-09-10 23:24:57 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.13.6

Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545