大括号扩展库(brace-expansion library)会生成包含公共前缀和后缀的任意字符串。在版本 1.1.21、2.1.7、3.0.9 和 5.0.12 之前, 函数在处理带有大量尾部闭合大括号(如 形式)的不可信模式时,会为每个尾部闭合大括号重启一次扫描。随着工作字符串长度线性增长,连续对完整输入的重扫操作会导致 CPU 时间消耗和内存压力呈二次方增长,从而可能阻塞 Node.js 事件循环。进程最终能够恢复执行,因此该漏洞的影响属于可恢复的 CPU 拒绝服务(DoS)。此问题已在版本 1.1.21、2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| juliangruber | brace-expansion | >= 4.0.0, < 5.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102278 | 7.5 HIGH | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhau |
| CVE-2026-102276 | 7.5 HIGH | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustio |
No comments yet