Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 2 min read

CVE-2026-102278: CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion

CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion Vulnerability ID: CVE-2026-102278 CVSS Score: 7.5 Published: 2026-09-29 A stack-based Denial of Service (DoS) vulnerabilit

CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion

Vulnerability ID: CVE-2026-102278
CVSS Score: 7.5
Published: 2026-09-29

A stack-based Denial of Service (DoS) vulnerability via uncontrolled recursion in the brace-expansion library prior to versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11 allows unauthenticated remote attackers to trigger native stack exhaustion, terminating the Node.js process via a crafted payload containing deeply nested brace groups.

TL;DR

Uncontrolled recursion in nested brace groups allows unauthenticated attackers to crash the Node.js process via a stack overflow using compact (~6KB) inputs.

โš ๏ธ Exploit Status: POC

Technical Details

  • CWE ID: CWE-674
  • Attack Vector: Network (Unauthenticated)
  • CVSS: 7.5 (High)
  • EPSS: 0.0035 (26th percentile)
  • Impact: Denial of Service (Process Termination)
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications processing untrusted shell-like patterns or glob vectors via brace-expansion.
  • Libraries utilizing brace-expansion transitively, such as older versions of minimatch or glob parsers.
  • brace-expansion: < 1.1.20 (Fixed in: 1.1.20)
  • brace-expansion: >= 2.0.0, < 2.1.6 (Fixed in: 2.1.6)
  • brace-expansion: >= 3.0.0, < 3.0.8 (Fixed in: 3.0.8)
  • brace-expansion: >= 4.0.0, < 5.0.11 (Fixed in: 5.0.11)

Code Analysis

Commit: 935d78f

Bound nesting recursion using EXPANSION_MAX_DEPTH in TypeScript module.

Commit: de84f14

Add maxDepth configuration and depth monitoring on nested expands for ESM.

Commit: 1efee7c

Implement recursion depths and legacy ES5 compatibility variables.

Exploit Details

  • GitHub Advisory: Security advisory details containing vulnerability mechanics and reproduction methods.

Mitigation Strategies

  • Upgrade dependency to patched versions across all active branches.
  • Sanitize and restrict input pattern complexity at application entry points.
  • Employ process managers (e.g., PM2) to ensure auto-restart capability upon crash events.

Remediation Steps:

  1. Identify vulnerable versions of brace-expansion using 'npm ls brace-expansion' or Software Composition Analysis.
  2. Force update of deep dependencies using package manager resolutions or overrides if transitive.
  3. In npm projects using version 5, execute: npm install [email protected]
  4. Verify the application does not crash when supplied with deeply nested brace patterns.

References

Read the full report for CVE-2026-102278 on our website for more details including interactive diagrams and full exploit analysis.

๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.