Fedora Account System
Red Hat Associate
Red Hat Customer
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47060 https://access.redhat.com/errata/RHSA-2026:47060
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:47059 https://access.redhat.com/errata/RHSA-2026:47059
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47057 https://access.redhat.com/errata/RHSA-2026:47057
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:47058 https://access.redhat.com/errata/RHSA-2026:47058
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48032 https://access.redhat.com/errata/RHSA-2026:48032
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48034 https://access.redhat.com/errata/RHSA-2026:48034
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:48033 https://access.redhat.com/errata/RHSA-2026:48033
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:52394 https://access.redhat.com/errata/RHSA-2026:52394
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:52399 https://access.redhat.com/errata/RHSA-2026:52399
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:53298 https://access.redhat.com/errata/RHSA-2026:53298
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590
This issue has been addressed in the following products: Red Hat AMQ Broker 7.14.1 Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488
This issue has been addressed in the following products: Red Hat AMQ Broker 7.13.6 Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545