brace-expansion 库会生成包含共同前缀和后缀的任意字符串。在版本 1.1.20、2.1.6、3.0.8 和 5.0.11 之前,深度嵌套的大括号组会导致 expand_() 函数在逗号成员和单集合展开位置处,每嵌套一层就递归一次。这会在使用输出限制之前耗尽原生调用栈,并可能导致 Node.js 进程终止。expand_ 函数对嵌套的大括号替代项和单部分集合执行无控制的递归。当向 expand_ 和 expand 函数提供来自不受信任来源的、深度嵌套的大括号组时,该函数受影响。逗号成员和单集合也受影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| juliangruber | brace-expansion | >= 4.0.0, < 5.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102276 | 7.5 HIGH | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustio |
| CVE-2026-102277 | 5.3 MEDIUM | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of ser |
No comments yet