CVE-2026-102278: Juliangruber Brace-Expansion

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.

Affected products

  • Juliangruber Brace-Expansion: from 4.0.0, before 5.0.11 (fixed in 5.0.11); from 3.0.0, before 3.0.8 (fixed in 3.0.8); from 2.0.0, before 2.1.6 (fixed in 2.1.6); before 1.1.20 (fixed in 1.1.20)

Published 2026-09-28. Last modified 2026-10-01.