← Back

CVE-2026-69152

nvd nist
Published: Aug 3, 2026Modified: Aug 5, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

Affected (4)

1 product
Brace Expansion
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Juliangruber
Before 1.1.18
From 2.0.0 to 2.1.4
From 3.0.0 to 3.0.6
From 4.0.0 to 5.0.9

Timeline

No history available yet.