CVE-2018-1109: Braces Project Braces

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

Affected products

Published 2021-03-30. Last modified 2026-06-17.