GHSA-qhr7-859c-m2p7: High severity npm/brace-expansion vulnerability

Published Sep 29, 2026
·
Updated

Summary

expand() recurses once per level of brace nesting. Deeply nested input exhausts the native stack and crashes the process.

This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the tail iterative (recursion on m.post, driven by how many groups are chained). Nesting depth drives a different recursion that the tail fix never touched, so the documented constant-stack-depth guarantee only ever covered chained input, not nested input.

It is also distinct from GHSA-6j4f-fj2g-mc7p, which fixed recursion in parseCommaParts(). Both payloads below still crash with that fix applied.

Two recursion sites

Comma members. Each alternative of a brace set is expanded by a recursive call, so nesting a set inside every alternative recurses once per level:

js expand('{a,'.repeat(4000) + 'z' + '}'.repeat(4000)) // RangeError: Maximum call stack size exceeded

Crashes at depth 3,907 - about 15.6 KB of input.

Single set. A brace set whose body parses to a single part is expanded by a recursive call before being re-wrapped (x{{a,b}}y -> x{a}y x{b}y), which recurses once per nesting level:

js expand('{'.repeat(3200) + 'a,b' + '}'.repeat(3200)) // RangeError: Maximum call stack size exceeded

Crashes at depth 3,125 - about 6.25 KB of input. This is the cheapest stack-exhaustion payload known against this package: roughly a quarter the input of GHSA-6j4f-fj2g-mc7p (29 KB), and about a tenth of minimatch's MAXPATTERNLENGTH (65,536).

Why max and maxLength do not help

Both crashes happen while recursing into sub-expansions, before the result set grows. The payloads produce almost no output - the single-set case yields 2 results - so neither bound is ever the limiter. expand(payload, { max: 1, maxLength: 1 }) still overflows.

Impact

Any application passing an untrusted string to expand(), directly or through minimatch / glob as a user-supplied glob pattern, can be crashed. In Node a RangeError the application does not catch terminates the process, so a server globbing user input is exposed to remote unauthenticated denial of service.

Availability only. No code execution, no data exposure.

Affected versions

Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, at near-identical depths on every line (single set: 3,125 on all four; comma members: 3,907-4,102). Not a regression from any recent fix - the gap predates them.

Patch

A maxDepth bound (default EXPANSIONMAXDEPTH) is threaded through expand(). Past the cap a group is treated as non-expanding and returned literally, which is how the parser already handles a group that cannot expand. This matches the existing max / maxLength caps, which truncate rather than throw, so expand() continues never to throw on any input.

The default sits far above any realistic nesting depth and well below the crash threshold.

Affected Software

4 affected componentsFixes available
npm/brace-expansion<1.1.20
1.1.20
npm/brace-expansion>=2.0.0<2.1.6
2.1.6
npm/brace-expansion>=3.0.0<3.0.8
3.0.8
npm/brace-expansion>=4.0.0<5.0.11
5.0.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 1.1.20
  2. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 2.1.6
  3. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 3.0.8
  4. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 5.0.11
  5. Configuration

    Enforce a maxDepth bound in expand_() so that past the cap a brace group is treated as non-expanding and returned literally.

    expand() maxDepth = EXPANSION_MAX_DEPTH

Event History

Sep 29, 2026
Advisory Published
via GitHub·11:45 PM
Data Sourced
via GitHub·11:45 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What input patterns can trigger the crash?

Deeply nested brace expressions can exhaust the native stack through either nested comma-member alternatives or nested single-part brace sets. The advisory reports a crash at nesting depth 3,907 for the comma-member pattern, using about 15.6 KB of input.

2

Does the earlier iterative-tail change prevent this denial of service?

No. That change addressed recursion driven by chained groups in m.post, while this issue is driven by brace nesting depth. The described payloads still crash with the tail fix applied.

3

Does the parseCommaParts() recursion fix address this issue?

No. The advisory states that both demonstrated nested-input payloads still crash after the parseCommaParts() fix is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203