CVE-2026-69152: The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while con
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69152
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69152 | coverage & exploitation status | NVD · CVE.org |
More from NVD Recent CVEs
- unknownCVE-2026-69153: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming t…2026-08-03
- unknownCVE-2026-69151: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- unknownCVE-2026-69149: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- unknownCVE-2026-68945: Angular is a development platform for building mobile and desktop web applications using TypeS…2026-08-03
- mediumCVE-2026-68930: Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped …2026-08-03