Overview
A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the expand() function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.
Vendor advisories
- RHSA-2026:48151 · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · advisory
- RHSA-2026:53298 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-11 · advisory
- RHSA-2026:52394 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-10 · advisory
- RHSA-2026:48033 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · advisory
- RHSA-2026:48032 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · advisory
- RHSA-2026:48034 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · advisory
- RHSA-2026:47059 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · advisory
- RHSA-2026:47060 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · advisory
- RHSA-2026:52399 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-10 · advisory
- RHSA-2026:47058 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · advisory
- RHSA-2026:47057 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · advisory
- Red Hat VEX · Important · affected: Confidential Compute Attestation, Exploit Intelligence, Node HealthCheck Operator, OpenShift Lightspeed, OpenShift Pipelines, OpenShift Service Mesh 2, … · no fix planned: Confidential Compute Attestation, OpenShift Service Mesh 2, Red Hat Directory Server 11, Red Hat Directory Server 12, … · updated 2026-09-21 · vex
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-21.
Affected:
- Confidential Compute Attestation
- Exploit Intelligence
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Connectivity Link 1
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Discovery 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat Single Sign-On 7
- Red Hat Trusted Profile Analyzer
Fixed:
- Cryostat 4 on RHEL 9
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat AMQ Broker 7.13.6
- Red Hat AMQ Broker 7.14.1
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Red Hat Hardened Images
- Red Hat Migration Toolkit 1.8
- Red Hat Migration Toolkit for Applications 8.1
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.17
- Red Hat OpenShift Container Platform 4.18
- Red Hat OpenShift Container Platform 4.19
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.29
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat Openshift Data Foundation 4.18
- Red Hat Openshift Data Foundation 4.19
- Red Hat Openshift Data Foundation 4.20
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
No fix planned:
- Confidential Compute Attestation
- OpenShift Service Mesh 2
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat OpenShift GitOps
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat Single Sign-On 7
- Exploit Intelligence
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Connectivity Link 1
- Red Hat Discovery 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift Container Platform 4
- Red Hat Trusted Profile Analyzer
Not affected:
- Cryostat 4 on RHEL 9
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat Edge Manager 1.1
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48151
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53298
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:52394
Workarounds / mitigations:
- There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.
Package advisory (CVE-2026-13149)
Affected packages:
brace-expansion >= 3.0.0, < 5.0.7
brace-expansion < 1.1.16
brace-expansion >= 2.0.0, < 2.1.2
Patched in:
brace-expansion 5.0.7
brace-expansion 1.1.16
brace-expansion 2.1.2
Source: https://github.com/advisories/GHSA-3jxr-9vmj-r5cp