CVE-2026-69152: Juliangruber Brace-Expansion
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
Affected products
- Juliangruber Brace-Expansion: before 1.1.18 (fixed in 1.1.18); from 2.0.0, before 2.1.4 (fixed in 2.1.4); from 3.0.0, before 3.0.6 (fixed in 3.0.6); from 4.0.0, before 5.0.9 (fixed in 5.0.9)
Published 2026-08-03. Last modified 2026-08-05.