{"id":"CVE-2026-13149","title":"brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)","summary":"A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1333","CWE-400","CWE-407"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.20","affected":["confidential_compute_attestation","exploit_intelligence","node_healthcheck_operator","openshift_lightspeed","openshift_pipelines","openshift_service_mesh 2","build_of_apache_camel_hawtio 4","build_of_apicurio_registry 3","build_of_podman_desktop","connectivity_link 1","directory_server 11","directory_server 12","directory_server 13","discovery 2","enterprise_linux_ai_rhel_ai 3","fuse 7","hardened_images","jboss_enterprise_application_platform 7","openshift_container_platform 4","openshift_gitops","single_sign_on 7","trusted_profile_analyzer","cryostat_4_on_rhel 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_extensions_channel_v_10","amq_broker 7.13.6","amq_broker 7.14.1","advanced_cluster_security 4.9","advanced_cluster_security_for_kubernetes 4.10","advanced_cluster_security_for_kubernetes 4.11","ansible_automation_platform 2.2","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","developer_hub 1.10","developer_hub 1.9"],"patched":["cryostat_4_on_rhel 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_extensions_channel_v_10","amq_broker 7.13.6","amq_broker 7.14.1","advanced_cluster_security 4.9","advanced_cluster_security_for_kubernetes 4.10","advanced_cluster_security_for_kubernetes 4.11","ansible_automation_platform 2.2","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","developer_hub 1.10","developer_hub 1.9","edge_manager 1.1","edge_manager 1.2","hardened_images","migration_toolkit 1.8","migration_toolkit_for_applications 8.1","openshift_ai 2.25","openshift_ai 3.4","openshift_container_platform 4.17","openshift_container_platform 4.18","openshift_container_platform 4.19","openshift_container_platform 4.20","openshift_container_platform 4.21","openshift_container_platform 4.22","openshift_dev_spaces 3.29","openshift_dev_spaces 3.30","openshift_data_foundation 4.18","openshift_data_foundation 4.19","openshift_data_foundation 4.20","quay 3.10","quay 3.12","quay 3.15","quay 3.16"],"published":"2026-06-30","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:32:36+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-13149"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494813"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13149"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13149"},{"url":"https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754"},{"url":"https://www.npmjs.com/package/brace-expansion"},{"url":"https://access.redhat.com/errata/RHSA-2026:48151"},{"url":"https://access.redhat.com/errata/RHSA-2026:53298"},{"url":"https://access.redhat.com/errata/RHSA-2026:52394"},{"url":"https://access.redhat.com/errata/RHSA-2026:48033"},{"url":"https://access.redhat.com/errata/RHSA-2026:48032"},{"url":"https://access.redhat.com/errata/RHSA-2026:48034"},{"url":"https://access.redhat.com/errata/RHSA-2026:47059"},{"url":"https://access.redhat.com/errata/RHSA-2026:47060"},{"url":"https://access.redhat.com/errata/RHSA-2026:52399"},{"url":"https://access.redhat.com/errata/RHSA-2026:47058"},{"url":"https://access.redhat.com/errata/RHSA-2026:47057"},{"url":"https://access.redhat.com/errata/RHSA-2026:57590"},{"url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"url":"https://access.redhat.com/errata/RHSA-2026:48872"},{"url":"https://access.redhat.com/errata/RHSA-2026:48913"},{"url":"https://access.redhat.com/errata/RHSA-2026:48891"},{"url":"https://access.redhat.com/errata/RHSA-2026:42815"},{"url":"https://access.redhat.com/errata/RHSA-2026:51162"},{"url":"https://access.redhat.com/errata/RHSA-2026:50357"},{"url":"https://access.redhat.com/errata/RHSA-2026:50479"},{"url":"https://access.redhat.com/errata/RHSA-2026:50340"},{"url":"https://access.redhat.com/errata/RHSA-2026:48126"},{"url":"https://access.redhat.com/errata/RHSA-2026:49642"},{"url":"https://access.redhat.com/errata/RHSA-2026:52768"},{"url":"https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-3jxr-9vmj-r5cp"},{"url":"https://github.com/juliangruber/brace-expansion/pull/122"},{"url":"https://github.com/juliangruber/brace-expansion/pull/123"},{"url":"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265"},{"url":"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"},{"url":"https://github.com/juliangruber/brace-expansion/releases/tag/v1.1.16"},{"url":"https://github.com/juliangruber/brace-expansion/releases/tag/v2.1.2"},{"url":"https://github.com/juliangruber/brace-expansion/releases/tag/v5.0.7"},{"url":"https://github.com/advisories/GHSA-3jxr-9vmj-r5cp"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00364,"epssPercentile":0.30112,"aliases":["GHSA-3jxr-9vmj-r5cp"],"ecosystem":"npm","ingestedAt":"2026-07-20T21:43:15.723Z","slug":"CVE-2026-13149","body":"## Overview\n\nA flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **RHSA-2026:48151** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48151)\n- **RHSA-2026:53298** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53298)\n- **RHSA-2026:52394** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52394)\n- **RHSA-2026:48033** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48033)\n- **RHSA-2026:48032** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48032)\n- **RHSA-2026:48034** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48034)\n- **RHSA-2026:47059** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47059)\n- **RHSA-2026:47060** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47060)\n- **RHSA-2026:52399** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52399)\n- **RHSA-2026:47058** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:47058)\n- **RHSA-2026:47057** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:47057)\n- **Red Hat VEX** · Important · affected: Confidential Compute Attestation, Exploit Intelligence, Node HealthCheck Operator, OpenShift Lightspeed, OpenShift Pipelines, OpenShift Service Mesh 2, … · no fix planned: Confidential Compute Attestation, OpenShift Service Mesh 2, Red Hat Directory Server 11, Red Hat Directory Server 12, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json)\n\n**brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity** — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-21.\n\nAffected:\n\n- Confidential Compute Attestation\n- Exploit Intelligence\n- Node HealthCheck Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Service Mesh 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 3\n- Red Hat Build of Podman Desktop\n- Red Hat Connectivity Link 1\n- Red Hat Directory Server 11\n- Red Hat Directory Server 12\n- Red Hat Directory Server 13\n- Red Hat Discovery 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Fuse 7\n- Red Hat Hardened Images\n- Red Hat JBoss Enterprise Application Platform 7\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat Single Sign-On 7\n- Red Hat Trusted Profile Analyzer\n\nFixed:\n\n- Cryostat 4 on RHEL 9\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux Extensions Channel (v. 10)\n- Red Hat AMQ Broker 7.13.6\n- Red Hat AMQ Broker 7.14.1\n- Red Hat Advanced Cluster Security 4.9\n- Red Hat Advanced Cluster Security for Kubernetes 4.10\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n- Red Hat Ansible Automation Platform 2.2\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat Edge Manager 1.1\n- Red Hat Edge Manager 1.2\n- Red Hat Hardened Images\n- Red Hat Migration Toolkit 1.8\n- Red Hat Migration Toolkit for Applications 8.1\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift Container Platform 4.17\n- Red Hat OpenShift Container Platform 4.18\n- Red Hat OpenShift Container Platform 4.19\n- Red Hat OpenShift Container Platform 4.20\n- Red Hat OpenShift Container Platform 4.21\n- Red Hat OpenShift Container Platform 4.22\n- Red Hat OpenShift Dev Spaces 3.29\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat Openshift Data Foundation 4.18\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n\nNo fix planned:\n\n- Confidential Compute Attestation\n- OpenShift Service Mesh 2\n- Red Hat Directory Server 11\n- Red Hat Directory Server 12\n- Red Hat Directory Server 13\n- Red Hat Fuse 7\n- Red Hat Hardened Images\n- Red Hat OpenShift GitOps\n- Red Hat JBoss Enterprise Application Platform 7\n- Red Hat Single Sign-On 7\n- Exploit Intelligence\n- Node HealthCheck Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 3\n- Red Hat Build of Podman Desktop\n- Red Hat Connectivity Link 1\n- Red Hat Discovery 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat Trusted Profile Analyzer\n\nNot affected:\n\n- Cryostat 4 on RHEL 9\n- Red Hat Advanced Cluster Security 4.9\n- Red Hat Advanced Cluster Security for Kubernetes 4.10\n- Red Hat Advanced Cluster Security for Kubernetes 4.11\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat Edge Manager 1.1\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48151\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53298\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:52394\n\nWorkarounds / mitigations:\n\n- There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.\n\n## Package advisory (CVE-2026-13149)\n\nAffected packages:\n\n- `brace-expansion >= 3.0.0, < 5.0.7`\n- `brace-expansion < 1.1.16`\n- `brace-expansion >= 2.0.0, < 2.1.2`\n\nPatched in:\n\n- `brace-expansion 5.0.7`\n- `brace-expansion 1.1.16`\n- `brace-expansion 2.1.2`\n\nSource: https://github.com/advisories/GHSA-3jxr-9vmj-r5cp","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":4943,"id":"CVE-2026-13149","ts":1788887218327,"field":"cvss","old":"5.3","new":"7.5"},{"seq":3826,"id":"CVE-2026-13149","ts":1788886351191,"field":"cvss","old":"7.5","new":"5.3"},{"seq":3213,"id":"CVE-2026-13149","ts":1788883134034,"field":"cvss","old":"5.3","new":"7.5"}]}