CVE-2026-33750: Juliangruber Brace-Expansion

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.

Affected products

  • Juliangruber Brace-Expansion: before 1.1.13 (fixed in 1.1.13); from 2.0.0, before 2.0.3 (fixed in 2.0.3); from 3.0.0, before 3.0.2 (fixed in 3.0.2); from 5.0.0, before 5.0.5 (fixed in 5.0.5)

Published 2026-03-27. Last modified 2026-06-17.