CVE-2026-102276: CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion
CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion Vulnerability ID: CVE-2026-102276 CVSS Score: 7.5 Published: 2026-09-29 CVE-2026-102276 is a high-severit
CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion
Vulnerability ID: CVE-2026-102276
CVSS Score: 7.5
Published: 2026-09-29
CVE-2026-102276 is a high-severity Denial of Service (DoS) vulnerability impacting the 'brace-expansion' library, a popular Node.js utility designed to expand brace patterns into combinatorial lists. Due to uncontrolled recursion and argument-list stack exhaustion within the internal parseCommaParts function, remote attackers can trigger an unhandled RangeError that abruptly terminates the Node.js process.
TL;DR
A denial-of-service vulnerability in brace-expansion allows unauthenticated remote attackers to crash Node.js applications by submitting maliciously nested or long comma-separated brace patterns, bypassing application-level limits.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400, CWE-674
- Attack Vector: Network (AV:N)
- CVSS v3.1: 7.5 (High)
- EPSS Score: 0.0035 (26.16th percentile)
- Impact Category: Denial of Service (Process Termination)
- Exploit Status: Proof-of-concept available
- CISA KEV Status: Not listed
Affected Systems
- brace-expansion Node.js library
-
brace-expansion: < 1.1.19 (Fixed in:
1.1.19) -
brace-expansion: >= 2.0.0, < 2.1.5 (Fixed in:
2.1.5) -
brace-expansion: >= 3.0.0, < 3.0.7 (Fixed in:
3.0.7) -
brace-expansion: >= 4.0.0, < 5.0.10 (Fixed in:
5.0.10)
Code Analysis
Commit: 0bcbfc0
Fix: Avoid stack overflow due to recursion
Commit: 316359e
Fix: Decouple recursion in 2.x branch
Commit: 5171e68
Fix: Remove stack allocation issues on 3.x branch
Commit: 6735c94
Fix: Decouple call stacks in 5.x branch
Mitigation Strategies
- Upgrade the brace-expansion library to patched security versions (1.1.19, 2.1.5, 3.0.7, or 5.0.10).
- Use npm overrides or yarn resolutions to force upstream transitive libraries like minimatch to load the patched dependency version.
- Incorporate input-validation logic to drop incoming parameters with excessive brace nesting levels (>100 nested characters) at the network border.
Remediation Steps:
- Scan the project dependencies using
npm list brace-expansionto identify vulnerable versions in use. - Update the project package.json to the correct safe version matching your active major release version.
- Inject a dependency resolution override block within your package.json metadata.
- Run
npm installoryarn installto update the lockfile structure and clear old transitive references.
References
- GitHub Security Advisory GHSA-6j4f-fj2g-mc7p
- NVD Vulnerability Details: CVE-2026-102276
- CVE Record: CVE-2026-102276
Read the full report for CVE-2026-102276 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.