Fedora Account System
Red Hat Associate
Red Hat Customer
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55541 https://access.redhat.com/errata/RHSA-2026:55541
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:58819 https://access.redhat.com/errata/RHSA-2026:58819
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416