REDHAT-BUG-2494813: Low severity brace-expansion vulnerability

Published Jun 30, 2026
·
Updated

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.

Affected Software

1 affected component
brace-expansion<=5.0.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate denial-of-service by limiting how untrusted input is allowed to reach the brace-expansion expand() function (e.g., reject or cap length/structure of crafted brace patterns that could cause exponential-time CPU consumption and event-loop blocking).

Event History

Jun 30, 2026
Data Sourced
via Red Hat·10:01 AM
DescriptionSeverityAffected Software
Jul 9, 58566
Event
via Red Hat·02:12 PM

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2494813?

The severity of REDHAT-BUG-2494813 is classified as low.

2

What type of vulnerability is described in REDHAT-BUG-2494813?

REDHAT-BUG-2494813 describes a denial of service vulnerability due to exponential-time complexity in the expand() function.

3

How does REDHAT-BUG-2494813 allow for denial of service?

REDHAT-BUG-2494813 allows for denial of service by processing crafted strings that lead to significant CPU consumption.

4

What is the affected software version for REDHAT-BUG-2494813?

The vulnerability in REDHAT-BUG-2494813 affects the brace-expansion software version 5.0.6 and below.

5

How can users mitigate REDHAT-BUG-2494813?

Users can mitigate REDHAT-BUG-2494813 by avoiding the use of untrusted input with the expand() function in brace-expansion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203