Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-102276: CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion

CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion Vulnerability ID: CVE-2026-102276 CVSS Score: 7.5 Published: 2026-09-29 CVE-2026-102276 is a high-severit

CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion

Vulnerability ID: CVE-2026-102276
CVSS Score: 7.5
Published: 2026-09-29

CVE-2026-102276 is a high-severity Denial of Service (DoS) vulnerability impacting the 'brace-expansion' library, a popular Node.js utility designed to expand brace patterns into combinatorial lists. Due to uncontrolled recursion and argument-list stack exhaustion within the internal parseCommaParts function, remote attackers can trigger an unhandled RangeError that abruptly terminates the Node.js process.

TL;DR

A denial-of-service vulnerability in brace-expansion allows unauthenticated remote attackers to crash Node.js applications by submitting maliciously nested or long comma-separated brace patterns, bypassing application-level limits.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400, CWE-674
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 7.5 (High)
  • EPSS Score: 0.0035 (26.16th percentile)
  • Impact Category: Denial of Service (Process Termination)
  • Exploit Status: Proof-of-concept available
  • CISA KEV Status: Not listed

Affected Systems

  • brace-expansion Node.js library
  • brace-expansion: < 1.1.19 (Fixed in: 1.1.19)
  • brace-expansion: >= 2.0.0, < 2.1.5 (Fixed in: 2.1.5)
  • brace-expansion: >= 3.0.0, < 3.0.7 (Fixed in: 3.0.7)
  • brace-expansion: >= 4.0.0, < 5.0.10 (Fixed in: 5.0.10)

Code Analysis

Commit: 0bcbfc0

Fix: Avoid stack overflow due to recursion

Commit: 316359e

Fix: Decouple recursion in 2.x branch

Commit: 5171e68

Fix: Remove stack allocation issues on 3.x branch

Commit: 6735c94

Fix: Decouple call stacks in 5.x branch

Mitigation Strategies

  • Upgrade the brace-expansion library to patched security versions (1.1.19, 2.1.5, 3.0.7, or 5.0.10).
  • Use npm overrides or yarn resolutions to force upstream transitive libraries like minimatch to load the patched dependency version.
  • Incorporate input-validation logic to drop incoming parameters with excessive brace nesting levels (>100 nested characters) at the network border.

Remediation Steps:

  1. Scan the project dependencies using npm list brace-expansion to identify vulnerable versions in use.
  2. Update the project package.json to the correct safe version matching your active major release version.
  3. Inject a dependency resolution override block within your package.json metadata.
  4. Run npm install or yarn install to update the lockfile structure and clear old transitive references.

References

Read the full report for CVE-2026-102276 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.