CVE-2026-25547: Isaacs Brace-Expansion

Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

Affected products

  • Isaacs Brace-Expansion: before 5.0.1 (fixed in 5.0.1)

Published 2026-02-04. Last modified 2026-06-17.