Alert IDs:
- 0c3cb174-69ac-47b8-824f-e7e7c613a3c0
- 2a30185b-0994-4034-873a-5d925519f040
- 653cd288-5cc3-459b-8c89-4651add8982d
- 77bac9e1-00e6-41ec-9d2c-a02d2d437e36
- 88e3641d-7d51-43e0-a1c7-9cfa22ec661b
- dfdbf07b-eed6-4854-9b55-0cdbb1de82c4
- e9e2a641-d7e6-49f0-8494-d0623f4b9efe
- f32adb50-ff30-485c-b0f1-4ff8163d65b1
Vulnerabilities in brace-expansion
Release: New release
Total Vulnerabilities: 8
Severity: MEDIUM (Score: 5.3)
Description:
Impact
A brace pattern with a zero step value (e.g., {1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory.
The loop in question:
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
test() is one of
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
The increment is computed as Math.abs(0) = 0, so the loop variable never advances. On a test machine, the process hangs for about 3.5 seconds and allocates roughly 1.9 GB of memory before throwing a RangeError. Setting max to any value has no effect because the limit is only checked at the output combination step, not during sequence generation.
This affects any application that passes untrusted strings to expand(), or by error sets a step value of 0. That includes tools built on minimatch/glob that resolve patterns from CLI arguments or config files. The input needed is just 10 bytes.
Patches
Upgrade to versions
A step increment of 0 is now sanitized to 1, which matches bash behavior.
Workarounds
Sanitize strings passed to expand() to ensure a step value of 0 is not used.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33750
Alert ID: 0c3cb174-69ac-47b8-824f-e7e7c613a3c0
Severity: HIGH (Score: 5.9)
Description:
Summary
expand() bounds the number of results it produces (the max option,
100_000 by default) but not their length. By chaining many brace groups,
an attacker keeps the result count under max while making every result grow
with the number of groups. Building max long results — plus the intermediate
arrays combined at each brace group — exhausts memory and crashes the Node
process with an uncatchable out-of-memory error. try/catch around
expand() does not help: the fatal error terminates the process.
A ~7.5 KB input ('{a,b}'.repeat(1500)) is enough to crash a default Node
process.
Details
For N chained brace groups such as '{a,b}'.repeat(N):
- the result count is
2^N, immediately capped at max (100_000), so the
max protection appears to hold, but
- each result is
N characters long, so the total output size is
max × N characters, which grows without bound in N.
expand_ combines each brace set with the fully-expanded tail:
const post = m.post.length ? expand_(m.post, max, false) : ['']
...
for (let j = 0; j < N.length; j++) {
for (let k = 0; k < post.length && expansions.length < max; k++) {
const expansion = pre + N[j] + post[k] // grows one group longer per level
...
expansions.push(expansion)
}
}
The loop guard expansions.length < max limits how many strings are built, but
nothing limits how long they get. Each recursion level materializes another
array of up to max strings, one character longer than the level below, and —
because V8 represents pre + N[j] + post[k] as a cons-string (rope) that
references post[k] — those intermediate strings stay reachable through the
whole chain. Memory therefore scales with max × N.
Measured on 5.0.7 ('{a,b}'.repeat(N), default max):
| groups (N) |
input bytes |
result count |
peak RSS |
| 20 |
100 |
100,000 |
~80 MB |
| 50 |
250 |
100,000 |
~214 MB |
| 100 |
500 |
100,000 |
~409 MB |
| 300 |
1,500 |
100,000 |
~1,148 MB |
| 1500 |
7,500 |
— |
OOM crash |
Proof of concept
const { expand } = require('brace-expansion')
// ~7.5 KB input — crashes the process with a fatal, uncatchable OOM:
// FATAL ERROR: ... JavaScript heap out of memory
try {
expand('{a,b}'.repeat(1500))
} catch (e) {
// never reached — the process is already dead
}
Impact
Any application that passes attacker-influenced strings to
brace-expansion.expand() — directly, or transitively via minimatch / glob
brace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.
Remediation
Upgrade to a patched release. The fix bounds the total number of characters a
single expand() call may accumulate (EXPANSION_MAX_LENGTH, default
4_000_000, configurable via a new maxLength option), applied inside the
output-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how max already truncates —
instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting max measure ~1M characters), so legitimate
input is unaffected.
After the fix, '{a,b}'.repeat(1500) returns a bounded, truncated result in
~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.
The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly O(N × maxLength) work on this input class). A streaming
rewrite that produces output in O(total output size) can be a non-urgent
follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to
expand() / glob brace patterns, or pass a small explicit max and
maxLength.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14257
Alert ID: 2a30185b-0994-4034-873a-5d925519f040
Severity: HIGH (Score: 5.9)
Description:
Summary
The maxLength mitigation added in 5.0.8 for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, so try/catch around expand() does not help.
A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.
Details
maxLength was enforced in combine(), the single place output grows. Two arrays are built before combine() runs, and neither was bounded.
1. Comma alternatives accumulate without a running total (memory exhaustion)
Each alternative in {a,b,c,...} is expanded by its own recursive expand_() call, so each receives a full, independent maxLength allowance. The results were then concatenated into a single values array with no cumulative limit:
values = []
for (let j = 0; j < n.length; j++) {
values.push.apply(values, expand_(n[j], max, maxLength, false))
}
acc = combine(acc, pre, values, max, maxLength, ...)
With A alternatives, values can reach A * maxLength characters before combine() gets a chance to truncate it. At the default maxLength of 4,000,000 and 400 alternatives, that is well past any default heap.
2. Padded sequences ignore maxLength while generating (CPU exhaustion)
expandSequence() was bounded by max (the result count) but never consulted maxLength. A padded sequence's element width follows the input, so {0...01..100000} with a wide pad generates max elements, each as wide as the input, only for combine() to discard all but a handful.
Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to max * width.
| pad width |
input bytes |
results kept |
time (5.0.8) |
time (patched) |
| 20,000 |
20 KB |
199 |
~7.3 s |
~20 ms |
| 100,000 |
100 KB |
39 |
~32 s |
~20 ms |
| 400,000 |
400 KB |
9 |
~124 s |
~18 ms |
Output is byte-identical before and after the fix; only the wasted work is removed.
Proof of concept
Memory exhaustion, against 5.0.8:
import { expand } from 'brace-expansion'
const part = '{' + '0'.repeat(50) + '1..100000}'
const input = '{' + Array(400).fill(part).join(',') + '}' // ~25 KB
try {
expand(input)
} catch (e) {
// never reached - the process is already dead
}
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
Aborted
Event-loop stall, against 5.0.8:
import { expand } from 'brace-expansion'
// ~400 KB input, returns 9 results after roughly two minutes of blocking CPU
expand('{' + '0'.repeat(400_000) + '1..100000}')
Impact
Denial of service. Any application that passes attacker-controlled input to expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled with try/catch.
Applications already on 5.0.8 are affected: the 5.0.8 mitigation does not cover these paths.
Patches
Both intermediate arrays are now bounded as they are built, using the same max and maxLength limits already applied in combine():
values tracks a running result count and character length while alternatives are appended, and stops once either bound is reached.
expandSequence() accepts maxLength and stops generating once the sequence's own characters reach it.
As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how max already behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.
Workarounds
If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns, or pass an explicitly small max and maxLength.
Note that a small maxLength alone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.
Credits
The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.
The sequence-generation issue was found while verifying that report.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-69152
Alert ID: 653cd288-5cc3-459b-8c89-4651add8982d
Severity: HIGH (Score: 4.8)
Description:
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In expand_, post is computed unconditionally at the top of the function, before the early-return branches that don't use it:
const post = m.post.length ? expand_(m.post, max, false) : ['']; // always recurses
...
if (!isSequence && !isOptions) {
if (m.post.match(/,(?!,).*\}/)) {
str = m.pre + '{' + m.body + escClose + m.post;
return expand_(str, max, true); // restart — `post` discarded
}
return [str];
}
For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but expand_ has already recursed into post over the entire remaining tail, only to throw the result away.
Each level therefore spawns two recursive expansions over essentially the same remaining work: T(n) = 2·T(n−1) ⇒ O(2ⁿ).
The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
| groups (n) |
input bytes |
time |
| 20 |
60 |
130 ms |
| 24 |
72 |
1.9 s |
| 26 |
78 |
7.8 s |
| 30 (PoC) |
90 |
~2 min |
Proof of concept
const { expand } = require('brace-expansion');
// 30 non-expanding groups, ~90 bytes — blocks for minutes:
expand('a{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{}');
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
- Defers computing post until after the early-return branches (and computes it locally in the $-suffix branch), so post is only expanded when a brace set actually expands and the value is used. This alone removes the exponential.
- Converts the {a},b} rewrite from recursion to an in-function loop, so a long run of rewrites cannot grow the call stack.
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-13149
Alert ID: 77bac9e1-00e6-41ec-9d2c-a02d2d437e36
Severity: HIGH (Score: 4.8)
Description:
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In expand_, post is computed unconditionally at the top of the function, before the early-return branches that don't use it:
const post = m.post.length ? expand_(m.post, max, false) : ['']; // always recurses
...
if (!isSequence && !isOptions) {
if (m.post.match(/,(?!,).*\}/)) {
str = m.pre + '{' + m.body + escClose + m.post;
return expand_(str, max, true); // restart — `post` discarded
}
return [str];
}
For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but expand_ has already recursed into post over the entire remaining tail, only to throw the result away.
Each level therefore spawns two recursive expansions over essentially the same remaining work: T(n) = 2·T(n−1) ⇒ O(2ⁿ).
The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
| groups (n) |
input bytes |
time |
| 20 |
60 |
130 ms |
| 24 |
72 |
1.9 s |
| 26 |
78 |
7.8 s |
| 30 (PoC) |
90 |
~2 min |
Proof of concept
const { expand } = require('brace-expansion');
// 30 non-expanding groups, ~90 bytes — blocks for minutes:
expand('a{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{},{}');
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
- Defers computing post until after the early-return branches (and computes it locally in the $-suffix branch), so post is only expanded when a brace set actually expands and the value is used. This alone removes the exponential.
- Converts the {a},b} rewrite from recursion to an in-function loop, so a long run of rewrites cannot grow the call stack.
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-13149
Alert ID: 88e3641d-7d51-43e0-a1c7-9cfa22ec661b
Severity: HIGH (Score: 5.9)
Description:
Summary
expand() bounds the number of results it produces (the max option,
100_000 by default) but not their length. By chaining many brace groups,
an attacker keeps the result count under max while making every result grow
with the number of groups. Building max long results — plus the intermediate
arrays combined at each brace group — exhausts memory and crashes the Node
process with an uncatchable out-of-memory error. try/catch around
expand() does not help: the fatal error terminates the process.
A ~7.5 KB input ('{a,b}'.repeat(1500)) is enough to crash a default Node
process.
Details
For N chained brace groups such as '{a,b}'.repeat(N):
- the result count is
2^N, immediately capped at max (100_000), so the
max protection appears to hold, but
- each result is
N characters long, so the total output size is
max × N characters, which grows without bound in N.
expand_ combines each brace set with the fully-expanded tail:
const post = m.post.length ? expand_(m.post, max, false) : ['']
...
for (let j = 0; j < N.length; j++) {
for (let k = 0; k < post.length && expansions.length < max; k++) {
const expansion = pre + N[j] + post[k] // grows one group longer per level
...
expansions.push(expansion)
}
}
The loop guard expansions.length < max limits how many strings are built, but
nothing limits how long they get. Each recursion level materializes another
array of up to max strings, one character longer than the level below, and —
because V8 represents pre + N[j] + post[k] as a cons-string (rope) that
references post[k] — those intermediate strings stay reachable through the
whole chain. Memory therefore scales with max × N.
Measured on 5.0.7 ('{a,b}'.repeat(N), default max):
| groups (N) |
input bytes |
result count |
peak RSS |
| 20 |
100 |
100,000 |
~80 MB |
| 50 |
250 |
100,000 |
~214 MB |
| 100 |
500 |
100,000 |
~409 MB |
| 300 |
1,500 |
100,000 |
~1,148 MB |
| 1500 |
7,500 |
— |
OOM crash |
Proof of concept
const { expand } = require('brace-expansion')
// ~7.5 KB input — crashes the process with a fatal, uncatchable OOM:
// FATAL ERROR: ... JavaScript heap out of memory
try {
expand('{a,b}'.repeat(1500))
} catch (e) {
// never reached — the process is already dead
}
Impact
Any application that passes attacker-influenced strings to
brace-expansion.expand() — directly, or transitively via minimatch / glob
brace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.
Remediation
Upgrade to a patched release. The fix bounds the total number of characters a
single expand() call may accumulate (EXPANSION_MAX_LENGTH, default
4_000_000, configurable via a new maxLength option), applied inside the
output-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how max already truncates —
instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting max measure ~1M characters), so legitimate
input is unaffected.
After the fix, '{a,b}'.repeat(1500) returns a bounded, truncated result in
~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.
The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly O(N × maxLength) work on this input class). A streaming
rewrite that produces output in O(total output size) can be a non-urgent
follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to
expand() / glob brace patterns, or pass a small explicit max and
maxLength.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14257
Alert ID: dfdbf07b-eed6-4854-9b55-0cdbb1de82c4
Severity: HIGH (Score: 5.9)
Description:
Summary
The maxLength mitigation added in 5.0.8 for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, so try/catch around expand() does not help.
A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.
Details
maxLength was enforced in combine(), the single place output grows. Two arrays are built before combine() runs, and neither was bounded.
1. Comma alternatives accumulate without a running total (memory exhaustion)
Each alternative in {a,b,c,...} is expanded by its own recursive expand_() call, so each receives a full, independent maxLength allowance. The results were then concatenated into a single values array with no cumulative limit:
values = []
for (let j = 0; j < n.length; j++) {
values.push.apply(values, expand_(n[j], max, maxLength, false))
}
acc = combine(acc, pre, values, max, maxLength, ...)
With A alternatives, values can reach A * maxLength characters before combine() gets a chance to truncate it. At the default maxLength of 4,000,000 and 400 alternatives, that is well past any default heap.
2. Padded sequences ignore maxLength while generating (CPU exhaustion)
expandSequence() was bounded by max (the result count) but never consulted maxLength. A padded sequence's element width follows the input, so {0...01..100000} with a wide pad generates max elements, each as wide as the input, only for combine() to discard all but a handful.
Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to max * width.
| pad width |
input bytes |
results kept |
time (5.0.8) |
time (patched) |
| 20,000 |
20 KB |
199 |
~7.3 s |
~20 ms |
| 100,000 |
100 KB |
39 |
~32 s |
~20 ms |
| 400,000 |
400 KB |
9 |
~124 s |
~18 ms |
Output is byte-identical before and after the fix; only the wasted work is removed.
Proof of concept
Memory exhaustion, against 5.0.8:
import { expand } from 'brace-expansion'
const part = '{' + '0'.repeat(50) + '1..100000}'
const input = '{' + Array(400).fill(part).join(',') + '}' // ~25 KB
try {
expand(input)
} catch (e) {
// never reached - the process is already dead
}
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
Aborted
Event-loop stall, against 5.0.8:
import { expand } from 'brace-expansion'
// ~400 KB input, returns 9 results after roughly two minutes of blocking CPU
expand('{' + '0'.repeat(400_000) + '1..100000}')
Impact
Denial of service. Any application that passes attacker-controlled input to expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled with try/catch.
Applications already on 5.0.8 are affected: the 5.0.8 mitigation does not cover these paths.
Patches
Both intermediate arrays are now bounded as they are built, using the same max and maxLength limits already applied in combine():
values tracks a running result count and character length while alternatives are appended, and stops once either bound is reached.
expandSequence() accepts maxLength and stops generating once the sequence's own characters reach it.
As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how max already behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.
Workarounds
If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns, or pass an explicitly small max and maxLength.
Note that a small maxLength alone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.
Credits
The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.
The sequence-generation issue was found while verifying that report.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-69152
Alert ID: e9e2a641-d7e6-49f0-8494-d0623f4b9efe
Severity: MEDIUM (Score: 5.3)
Description:
Impact
A brace pattern with a zero step value (e.g., {1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory.
The loop in question:
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
test() is one of
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
The increment is computed as Math.abs(0) = 0, so the loop variable never advances. On a test machine, the process hangs for about 3.5 seconds and allocates roughly 1.9 GB of memory before throwing a RangeError. Setting max to any value has no effect because the limit is only checked at the output combination step, not during sequence generation.
This affects any application that passes untrusted strings to expand(), or by error sets a step value of 0. That includes tools built on minimatch/glob that resolve patterns from CLI arguments or config files. The input needed is just 10 bytes.
Patches
Upgrade to versions
A step increment of 0 is now sanitized to 1, which matches bash behavior.
Workarounds
Sanitize strings passed to expand() to ensure a step value of 0 is not used.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33750
Alert ID: f32adb50-ff30-485c-b0f1-4ff8163d65b1
Alert IDs:
Vulnerabilities in brace-expansion
Release: New release
Total Vulnerabilities: 8
1. CVE-2026-33750
Severity: MEDIUM (Score: 5.3)
Description:
Impact
A brace pattern with a zero step value (e.g.,
{1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory.The loop in question:
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
test()is one ofhttps://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
The increment is computed as
Math.abs(0) = 0, so the loop variable never advances. On a test machine, the process hangs for about 3.5 seconds and allocates roughly 1.9 GB of memory before throwing aRangeError. Setting max to any value has no effect because the limit is only checked at the output combination step, not during sequence generation.This affects any application that passes untrusted strings to expand(), or by error sets a step value of
0. That includes tools built on minimatch/glob that resolve patterns from CLI arguments or config files. The input needed is just 10 bytes.Patches
Upgrade to versions
A step increment of 0 is now sanitized to 1, which matches bash behavior.
Workarounds
Sanitize strings passed to
expand()to ensure a step value of0is not used.Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33750
Alert ID: 0c3cb174-69ac-47b8-824f-e7e7c613a3c0
2. CVE-2026-14257
Severity: HIGH (Score: 5.9)
Description:
Summary
expand()bounds the number of results it produces (themaxoption,100_000by default) but not their length. By chaining many brace groups,an attacker keeps the result count under
maxwhile making every result growwith the number of groups. Building
maxlong results — plus the intermediatearrays combined at each brace group — exhausts memory and crashes the Node
process with an uncatchable out-of-memory error.
try/catcharoundexpand()does not help: the fatal error terminates the process.A ~7.5 KB input (
'{a,b}'.repeat(1500)) is enough to crash a default Nodeprocess.
Details
For
Nchained brace groups such as'{a,b}'.repeat(N):2^N, immediately capped atmax(100_000), so themaxprotection appears to hold, butNcharacters long, so the total output size ismax × Ncharacters, which grows without bound inN.expand_combines each brace set with the fully-expanded tail:The loop guard
expansions.length < maxlimits how many strings are built, butnothing limits how long they get. Each recursion level materializes another
array of up to
maxstrings, one character longer than the level below, and —because V8 represents
pre + N[j] + post[k]as a cons-string (rope) thatreferences
post[k]— those intermediate strings stay reachable through thewhole chain. Memory therefore scales with
max × N.Measured on
5.0.7('{a,b}'.repeat(N), defaultmax):Proof of concept
Impact
Any application that passes attacker-influenced strings to
brace-expansion.expand()— directly, or transitively viaminimatch/globbrace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.
Remediation
Upgrade to a patched release. The fix bounds the total number of characters a
single
expand()call may accumulate (EXPANSION_MAX_LENGTH, default4_000_000, configurable via a newmaxLengthoption), applied inside theoutput-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how
maxalready truncates —instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting
maxmeasure ~1M characters), so legitimateinput is unaffected.
After the fix,
'{a,b}'.repeat(1500)returns a bounded, truncated result in~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.
The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly
O(N × maxLength)work on this input class). A streamingrewrite that produces output in
O(total output size)can be a non-urgentfollow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to
expand()/ glob brace patterns, or pass a small explicitmaxandmaxLength.Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14257
Alert ID: 2a30185b-0994-4034-873a-5d925519f040
3. CVE-2026-69152
Severity: HIGH (Score: 5.9)
Description:
Summary
The
maxLengthmitigation added in5.0.8for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, sotry/catcharoundexpand()does not help.A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.
Details
maxLengthwas enforced incombine(), the single place output grows. Two arrays are built beforecombine()runs, and neither was bounded.1. Comma alternatives accumulate without a running total (memory exhaustion)
Each alternative in
{a,b,c,...}is expanded by its own recursiveexpand_()call, so each receives a full, independentmaxLengthallowance. The results were then concatenated into a singlevaluesarray with no cumulative limit:With
Aalternatives,valuescan reachA * maxLengthcharacters beforecombine()gets a chance to truncate it. At the defaultmaxLengthof 4,000,000 and 400 alternatives, that is well past any default heap.2. Padded sequences ignore
maxLengthwhile generating (CPU exhaustion)expandSequence()was bounded bymax(the result count) but never consultedmaxLength. A padded sequence's element width follows the input, so{0...01..100000}with a wide pad generatesmaxelements, each as wide as the input, only forcombine()to discard all but a handful.Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to
max * width.Output is byte-identical before and after the fix; only the wasted work is removed.
Proof of concept
Memory exhaustion, against
5.0.8:Event-loop stall, against
5.0.8:Impact
Denial of service. Any application that passes attacker-controlled input to
expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled withtry/catch.Applications already on
5.0.8are affected: the5.0.8mitigation does not cover these paths.Patches
Both intermediate arrays are now bounded as they are built, using the same
maxandmaxLengthlimits already applied incombine():valuestracks a running result count and character length while alternatives are appended, and stops once either bound is reached.expandSequence()acceptsmaxLengthand stops generating once the sequence's own characters reach it.As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how
maxalready behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.Workarounds
If upgrading is not immediately possible, avoid passing untrusted input to
expand()or to glob brace patterns, or pass an explicitly smallmaxandmaxLength.Note that a small
maxLengthalone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.Credits
The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.
The sequence-generation issue was found while verifying that report.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-69152
Alert ID: 653cd288-5cc3-459b-8c89-4651add8982d
4. CVE-2026-13149
Severity: HIGH (Score: 4.8)
Description:
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In
expand_,postis computed unconditionally at the top of the function, before the early-return branches that don't use it:For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but
expand_has already recursed into post over the entire remaining tail, only to throw the result away.Each level therefore spawns two recursive expansions over essentially the same remaining work:
T(n) = 2·T(n−1) ⇒ O(2ⁿ).The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
Proof of concept
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-13149
Alert ID: 77bac9e1-00e6-41ec-9d2c-a02d2d437e36
5. CVE-2026-13149
Severity: HIGH (Score: 4.8)
Description:
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In
expand_,postis computed unconditionally at the top of the function, before the early-return branches that don't use it:For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but
expand_has already recursed into post over the entire remaining tail, only to throw the result away.Each level therefore spawns two recursive expansions over essentially the same remaining work:
T(n) = 2·T(n−1) ⇒ O(2ⁿ).The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
Proof of concept
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-13149
Alert ID: 88e3641d-7d51-43e0-a1c7-9cfa22ec661b
6. CVE-2026-14257
Severity: HIGH (Score: 5.9)
Description:
Summary
expand()bounds the number of results it produces (themaxoption,100_000by default) but not their length. By chaining many brace groups,an attacker keeps the result count under
maxwhile making every result growwith the number of groups. Building
maxlong results — plus the intermediatearrays combined at each brace group — exhausts memory and crashes the Node
process with an uncatchable out-of-memory error.
try/catcharoundexpand()does not help: the fatal error terminates the process.A ~7.5 KB input (
'{a,b}'.repeat(1500)) is enough to crash a default Nodeprocess.
Details
For
Nchained brace groups such as'{a,b}'.repeat(N):2^N, immediately capped atmax(100_000), so themaxprotection appears to hold, butNcharacters long, so the total output size ismax × Ncharacters, which grows without bound inN.expand_combines each brace set with the fully-expanded tail:The loop guard
expansions.length < maxlimits how many strings are built, butnothing limits how long they get. Each recursion level materializes another
array of up to
maxstrings, one character longer than the level below, and —because V8 represents
pre + N[j] + post[k]as a cons-string (rope) thatreferences
post[k]— those intermediate strings stay reachable through thewhole chain. Memory therefore scales with
max × N.Measured on
5.0.7('{a,b}'.repeat(N), defaultmax):Proof of concept
Impact
Any application that passes attacker-influenced strings to
brace-expansion.expand()— directly, or transitively viaminimatch/globbrace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.
Remediation
Upgrade to a patched release. The fix bounds the total number of characters a
single
expand()call may accumulate (EXPANSION_MAX_LENGTH, default4_000_000, configurable via a newmaxLengthoption), applied inside theoutput-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how
maxalready truncates —instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting
maxmeasure ~1M characters), so legitimateinput is unaffected.
After the fix,
'{a,b}'.repeat(1500)returns a bounded, truncated result in~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.
The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly
O(N × maxLength)work on this input class). A streamingrewrite that produces output in
O(total output size)can be a non-urgentfollow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to
expand()/ glob brace patterns, or pass a small explicitmaxandmaxLength.Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-14257
Alert ID: dfdbf07b-eed6-4854-9b55-0cdbb1de82c4
7. CVE-2026-69152
Severity: HIGH (Score: 5.9)
Description:
Summary
The
maxLengthmitigation added in5.0.8for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, sotry/catcharoundexpand()does not help.A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.
Details
maxLengthwas enforced incombine(), the single place output grows. Two arrays are built beforecombine()runs, and neither was bounded.1. Comma alternatives accumulate without a running total (memory exhaustion)
Each alternative in
{a,b,c,...}is expanded by its own recursiveexpand_()call, so each receives a full, independentmaxLengthallowance. The results were then concatenated into a singlevaluesarray with no cumulative limit:With
Aalternatives,valuescan reachA * maxLengthcharacters beforecombine()gets a chance to truncate it. At the defaultmaxLengthof 4,000,000 and 400 alternatives, that is well past any default heap.2. Padded sequences ignore
maxLengthwhile generating (CPU exhaustion)expandSequence()was bounded bymax(the result count) but never consultedmaxLength. A padded sequence's element width follows the input, so{0...01..100000}with a wide pad generatesmaxelements, each as wide as the input, only forcombine()to discard all but a handful.Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to
max * width.Output is byte-identical before and after the fix; only the wasted work is removed.
Proof of concept
Memory exhaustion, against
5.0.8:Event-loop stall, against
5.0.8:Impact
Denial of service. Any application that passes attacker-controlled input to
expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled withtry/catch.Applications already on
5.0.8are affected: the5.0.8mitigation does not cover these paths.Patches
Both intermediate arrays are now bounded as they are built, using the same
maxandmaxLengthlimits already applied incombine():valuestracks a running result count and character length while alternatives are appended, and stops once either bound is reached.expandSequence()acceptsmaxLengthand stops generating once the sequence's own characters reach it.As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how
maxalready behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.Workarounds
If upgrading is not immediately possible, avoid passing untrusted input to
expand()or to glob brace patterns, or pass an explicitly smallmaxandmaxLength.Note that a small
maxLengthalone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.Credits
The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.
The sequence-generation issue was found while verifying that report.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-69152
Alert ID: e9e2a641-d7e6-49f0-8494-d0623f4b9efe
8. CVE-2026-33750
Severity: MEDIUM (Score: 5.3)
Description:
Impact
A brace pattern with a zero step value (e.g.,
{1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory.The loop in question:
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
test()is one ofhttps://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
The increment is computed as
Math.abs(0) = 0, so the loop variable never advances. On a test machine, the process hangs for about 3.5 seconds and allocates roughly 1.9 GB of memory before throwing aRangeError. Setting max to any value has no effect because the limit is only checked at the output combination step, not during sequence generation.This affects any application that passes untrusted strings to expand(), or by error sets a step value of
0. That includes tools built on minimatch/glob that resolve patterns from CLI arguments or config files. The input needed is just 10 bytes.Patches
Upgrade to versions
A step increment of 0 is now sanitized to 1, which matches bash behavior.
Workarounds
Sanitize strings passed to
expand()to ensure a step value of0is not used.Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33750
Alert ID: f32adb50-ff30-485c-b0f1-4ff8163d65b1