Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102277— brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service

Quick assessment

Affected
juliangruber brace-expansion
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

大括号扩展库(brace-expansion library)会生成包含公共前缀和后缀的任意字符串。在版本 1.1.21、2.1.7、3.0.9 和 5.0.12 之前, 函数在处理带有大量尾部闭合大括号(如 形式)的不可信模式时,会为每个尾部闭合大括号重启一次扫描。随着工作字符串长度线性增长,连续对完整输入的重扫操作会导致 CPU 时间消耗和内存压力呈二次方增长,从而可能阻塞 Node.js 事件循环。进程最终能够恢复执行,因此该漏洞的影响属于可恢复的 CPU 拒绝服务(DoS)。此问题已在版本 1.1.21、2

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102277

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
juliangruber brace-expansion >= 4.0.0, < 5.0.12 -

II. Public POCs for CVE-2026-102277

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102277

请登录查看更多情报信息。

Other References for CVE-2026-102277 (5)

Same Patch Batch · juliangruber · 2026-09-28 · 3 CVEs total

CVE-2026-102278 7.5 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhau
CVE-2026-102276 7.5 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustio

IV. Related Vulnerabilities

V. Comments for CVE-2026-102277

No comments yet


Leave a comment