GHSA-rgw5-rvv9-x895: High severity npm/brace-expansion vulnerability

Published Aug 3, 2026
·
Updated

Summary

The maxLength mitigation added in 5.0.8 for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, so try/catch around expand() does not help.

A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.

Details

maxLength was enforced in combine(), the single place output grows. Two arrays are built before combine() runs, and neither was bounded.

1. Comma alternatives accumulate without a running total (memory exhaustion)

Each alternative in {a,b,c,...} is expanded by its own recursive expand() call, so each receives a full, independent maxLength allowance. The results were then concatenated into a single values array with no cumulative limit:

js values = [] for (let j = 0; j < n.length; j++) { values.push.apply(values, expand(n[j], max, maxLength, false)) }

acc = combine(acc, pre, values, max, maxLength, ...)

With A alternatives, values can reach A maxLength characters before combine() gets a chance to truncate it. At the default maxLength of 4,000,000 and 400 alternatives, that is well past any default heap.

2. Padded sequences ignore maxLength while generating (CPU exhaustion)

expandSequence() was bounded by max (the result count) but never consulted maxLength. A padded sequence's element width follows the input, so {0...01..100000} with a wide pad generates max elements, each as wide as the input, only for combine() to discard all but a handful.

Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to max width.

| pad width | input bytes | results kept | time (5.0.8) | time (patched) | |---|---|---|---|---| | 20,000 | 20 KB | 199 | ~7.3 s | ~20 ms | | 100,000 | 100 KB | 39 | ~32 s | ~20 ms | | 400,000 | 400 KB | 9 | ~124 s | ~18 ms |

Output is byte-identical before and after the fix; only the wasted work is removed.

Proof of concept

Memory exhaustion, against 5.0.8:

js import { expand } from 'brace-expansion'

const part = '{' + '0'.repeat(50) + '1..100000}' const input = '{' + Array(400).fill(part).join(',') + '}' // ~25 KB

try { expand(input) } catch (e) { // never reached - the process is already dead }

FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory Aborted

Event-loop stall, against 5.0.8:

js import { expand } from 'brace-expansion'

// ~400 KB input, returns 9 results after roughly two minutes of blocking CPU expand('{' + '0'.repeat(400000) + '1..100000}')

Impact

Denial of service. Any application that passes attacker-controlled input to expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled with try/catch.

Applications already on 5.0.8 are affected: the 5.0.8 mitigation does not cover these paths.

Patches

Both intermediate arrays are now bounded as they are built, using the same max and maxLength limits already applied in combine():

- values tracks a running result count and character length while alternatives are appended, and stops once either bound is reached. - expandSequence() accepts maxLength and stops generating once the sequence's own characters reach it.

As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how max already behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.

Workarounds

If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns, or pass an explicitly small max and maxLength.

Note that a small maxLength alone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.

Credits

The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.

The sequence-generation issue was found while verifying that report.

Affected Software

4 affected componentsFixes available
npm/brace-expansion>=4.0.0<5.0.9
5.0.9
npm/brace-expansion>=3.0.0<3.0.6
3.0.6
npm/brace-expansion>=2.0.0<2.1.4
2.1.4
npm/brace-expansion<1.1.18
1.1.18

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 5.0.9
  2. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 3.0.6
  3. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 2.1.4
  4. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 1.1.18
  5. Upgrade

    Upgrade brace-expansion to a version that resolves this vulnerability.

    Fixed in 5.0.8
  6. Configuration

    If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns; pass an explicitly small max AND maxLength so expansion bounds are applied.

    brace-expansion max = explicitly small

Event History

Aug 3, 2026
Advisory Published
via GitHub·04:35 PM
Data Sourced
via GitHub·04:35 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-rgw5-rvv9-x895?

The severity of GHSA-rgw5-rvv9-x895 is rated high, with a CVSS score of 7.5.

2

What is the risk associated with GHSA-rgw5-rvv9-x895?

The risk associated with GHSA-rgw5-rvv9-x895 is categorized as a score of 43.

3

How do I fix GHSA-rgw5-rvv9-x895?

To mitigate GHSA-rgw5-rvv9-x895, you should upgrade to a patched version of the 'brace-expansion' package as per the recent advisories.

4

What software is affected by GHSA-rgw5-rvv9-x895?

GHSA-rgw5-rvv9-x895 affects the 'brace-expansion' package used in npm.

5

What specific vulnerability does GHSA-rgw5-rvv9-x895 address?

GHSA-rgw5-rvv9-x895 addresses an incomplete mitigation related to an out-of-memory error that can crash the Node process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203