CVE-2026-69152
EUVD-2026-5237003.08.2026, 17:16
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| juliangruber | brace-expansion | 𝑥 < 1.1.18 |
| juliangruber | brace-expansion | 2.0.0 ≤ 𝑥 < 2.1.4 |
| juliangruber | brace-expansion | 3.0.0 ≤ 𝑥 < 3.0.6 |
| juliangruber | brace-expansion | 4.0.0 ≤ 𝑥 < 5.0.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Vulnerability Media Exposure
References