Source: node-brace-expansion
Version: 2.1.4+~1.1.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for node-brace-expansion.

CVE-2026-102276[0]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10,
| crafted brace patterns can exhaust the native stack in
| parseCommaParts because parseCommaParts recursively processes the
| remainder once per brace group and uses push.apply to pass every
| element of a very large comma-part array as a function argument.
| Patterns containing many comma-separated brace groups trigger the
| recursive path, while the large array triggers the argument-array
| path without deep recursion. These paths cause recursive and
| argument-array native stack exhaustion before max or maxLength can
| limit output, potentially terminating the Node.js process in a
| process-terminating denial of service. This issue is fixed in
| versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.


CVE-2026-102277[1]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12,
| the expand function handles untrusted {a},b}-shaped patterns with
| many trailing closing braces by restarting its scan once for each
| trailing closing brace. The successive full-input rescans with
| linear working-string growth cause quadratic CPU time and memory
| pressure that can block the Node.js event loop. The process
| eventually recovers, making the impact a recoverable CPU denial of
| service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and
| 5.0.12.


CVE-2026-102278[2]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11,
| deeply nested brace groups cause expand_() to recurse once per
| nesting level at comma-member and single-set expansion sites,
| exhausting the native stack before output limits can apply and
| potentially terminating the Node.js process. expand_ performs
| uncontrolled recursion for nested brace alternatives and single-part
| sets. deeply nested brace groups supplied as an untrusted pattern.
| expand_ is affected. expand is affected. Comma members is affected.
| Single set is affected. native stack exhaustion during nested sub-
| expansion. process-terminating denial of service. This issue is
| fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102276
    https://www.cve.org/CVERecord?id=CVE-2026-102276
[1] https://security-tracker.debian.org/tracker/CVE-2026-102277
    https://www.cve.org/CVERecord?id=CVE-2026-102277
[2] https://security-tracker.debian.org/tracker/CVE-2026-102278
    https://www.cve.org/CVERecord?id=CVE-2026-102278

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to