Bug 2436942 (CVE-2026-25547) - CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
Summary: CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unboun...
Keywords:
Status: NEW
Alias: CVE-2026-25547
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-04 22:01 UTC by OSIDB Bzimport
Modified: 2026-02-06 15:04 UTC (History)
104 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-04 22:01:35 UTC
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.


Note You need to log in before you can comment on or make changes to this bug.