CVE-2026-102277: Juliangruber Brace-Expansion

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.

Affected products

  • Juliangruber Brace-Expansion: from 4.0.0, before 5.0.12 (fixed in 5.0.12); from 3.0.0, before 3.0.9 (fixed in 3.0.9); from 2.0.0, before 2.1.7 (fixed in 2.1.7); before 1.1.21 (fixed in 1.1.21)

Published 2026-09-28. Last modified 2026-09-30.