CVE-2026-102277 - Medium Severity Vulnerability
Vulnerable Libraries - brace-expansion-5.0.9.tgz, brace-expansion-2.1.4.tgz, brace-expansion-1.1.18.tgz
brace-expansion-5.0.9.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- eslint-plugin-import-x-4.17.1.tgz (Root Library)
- minimatch-10.2.5.tgz
- ❌ brace-expansion-5.0.9.tgz (Vulnerable Library)
brace-expansion-2.1.4.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.4.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- mocha-11.7.6.tgz (Root Library)
- glob-10.5.0.tgz
- minimatch-9.0.9.tgz
- ❌ brace-expansion-2.1.4.tgz (Vulnerable Library)
brace-expansion-1.1.18.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- eslint-plugin-jsx-a11y-6.10.2.tgz (Root Library)
- minimatch-3.1.5.tgz
- ❌ brace-expansion-1.1.18.tgz (Vulnerable Library)
Found in HEAD commit: 4f2a7131d9cdb72c0b6ec2df38bf840af14e67bb
Found in base branch: main
Vulnerability Details
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
Publish Date: 2026-09-28
URL: CVE-2026-102277
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: brace-expansion - 5.0.12
CVE-2026-102277 - Medium Severity Vulnerability
brace-expansion-5.0.9.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
brace-expansion-2.1.4.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.4.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
brace-expansion-1.1.18.tgz
Brace expansion as known from sh/bash
Library home page: https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: 4f2a7131d9cdb72c0b6ec2df38bf840af14e67bb
Found in base branch: main
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
Publish Date: 2026-09-28
URL: CVE-2026-102277
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: brace-expansion - 5.0.12