---
id: CVE-2026-13149
title: >-
  brace-expansion: Brace-expansion: Denial of Service due to exponential-time
  complexity (CVE-2026-13149)
summary: >-
  A flaw was found in brace-expansion. An attacker can exploit a vulnerability
  in the `expand()` function by providing a specially crafted string. This
  string, containing consecutive non-expanding brace groups, can trigger
  exponential-time c…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-1333
  - CWE-400
  - CWE-407
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.20
affected:
  - confidential_compute_attestation
  - exploit_intelligence
  - node_healthcheck_operator
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_service_mesh 2
  - build_of_apache_camel_hawtio 4
  - build_of_apicurio_registry 3
  - build_of_podman_desktop
  - connectivity_link 1
  - directory_server 11
  - directory_server 12
  - directory_server 13
  - discovery 2
  - enterprise_linux_ai_rhel_ai 3
  - fuse 7
  - hardened_images
  - jboss_enterprise_application_platform 7
  - openshift_container_platform 4
  - openshift_gitops
  - single_sign_on 7
  - trusted_profile_analyzer
  - cryostat_4_on_rhel 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_extensions_channel_v_10
  - amq_broker 7.13.6
  - amq_broker 7.14.1
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.10
  - developer_hub 1.9
patched:
  - cryostat_4_on_rhel 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_extensions_channel_v_10
  - amq_broker 7.13.6
  - amq_broker 7.14.1
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - developer_hub 1.10
  - developer_hub 1.9
  - edge_manager 1.1
  - edge_manager 1.2
  - hardened_images
  - migration_toolkit 1.8
  - migration_toolkit_for_applications 8.1
  - openshift_ai 2.25
  - openshift_ai 3.4
  - openshift_container_platform 4.17
  - openshift_container_platform 4.18
  - openshift_container_platform 4.19
  - openshift_container_platform 4.20
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_dev_spaces 3.29
  - openshift_dev_spaces 3.30
  - openshift_data_foundation 4.18
  - openshift_data_foundation 4.19
  - openshift_data_foundation 4.20
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
published: '2026-06-30'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T10:32:36+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-13149'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2494813'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-13149'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13149'
  - url: >-
      https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754
  - url: 'https://www.npmjs.com/package/brace-expansion'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48151'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53298'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52394'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48033'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48032'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48034'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47059'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47060'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52399'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47058'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47057'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57590'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66545'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66488'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48872'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48913'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48891'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42815'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51162'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50357'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49642'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52768'
  - url: >-
      https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-3jxr-9vmj-r5cp
  - url: 'https://github.com/juliangruber/brace-expansion/pull/122'
  - url: 'https://github.com/juliangruber/brace-expansion/pull/123'
  - url: >-
      https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265
  - url: >-
      https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95
  - url: 'https://github.com/juliangruber/brace-expansion/releases/tag/v1.1.16'
  - url: 'https://github.com/juliangruber/brace-expansion/releases/tag/v2.1.2'
  - url: 'https://github.com/juliangruber/brace-expansion/releases/tag/v5.0.7'
  - url: 'https://github.com/advisories/GHSA-3jxr-9vmj-r5cp'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00364
epssPercentile: 0.30112
aliases:
  - GHSA-3jxr-9vmj-r5cp
ecosystem: npm
ingestedAt: '2026-07-20T21:43:15.723Z'
---

## Overview

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **RHSA-2026:48151** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48151)
- **RHSA-2026:53298** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53298)
- **RHSA-2026:52394** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52394)
- **RHSA-2026:48033** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48033)
- **RHSA-2026:48032** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48032)
- **RHSA-2026:48034** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48034)
- **RHSA-2026:47059** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47059)
- **RHSA-2026:47060** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47060)
- **RHSA-2026:52399** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52399)
- **RHSA-2026:47058** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:47058)
- **RHSA-2026:47057** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:47057)
- **Red Hat VEX** · Important · affected: Confidential Compute Attestation, Exploit Intelligence, Node HealthCheck Operator, OpenShift Lightspeed, OpenShift Pipelines, OpenShift Service Mesh 2, … · no fix planned: Confidential Compute Attestation, OpenShift Service Mesh 2, Red Hat Directory Server 11, Red Hat Directory Server 12, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13149.json)

**brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity** — rated Important by Red Hat. Released 2026-06-30, updated 2026-09-21.

Affected:

- Confidential Compute Attestation
- Exploit Intelligence
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Connectivity Link 1
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Discovery 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat Single Sign-On 7
- Red Hat Trusted Profile Analyzer

Fixed:

- Cryostat 4 on RHEL 9
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat AMQ Broker 7.13.6
- Red Hat AMQ Broker 7.14.1
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Red Hat Hardened Images
- Red Hat Migration Toolkit 1.8
- Red Hat Migration Toolkit for Applications 8.1
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.17
- Red Hat OpenShift Container Platform 4.18
- Red Hat OpenShift Container Platform 4.19
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.29
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat Openshift Data Foundation 4.18
- Red Hat Openshift Data Foundation 4.19
- Red Hat Openshift Data Foundation 4.20
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16

No fix planned:

- Confidential Compute Attestation
- OpenShift Service Mesh 2
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat OpenShift GitOps
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat Single Sign-On 7
- Exploit Intelligence
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Connectivity Link 1
- Red Hat Discovery 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift Container Platform 4
- Red Hat Trusted Profile Analyzer

Not affected:

- Cryostat 4 on RHEL 9
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat Edge Manager 1.1

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48151
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:53298
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:52394

Workarounds / mitigations:

- There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.

## Package advisory (CVE-2026-13149)

Affected packages:

- `brace-expansion >= 3.0.0, < 5.0.7`
- `brace-expansion < 1.1.16`
- `brace-expansion >= 2.0.0, < 2.1.2`

Patched in:

- `brace-expansion 5.0.7`
- `brace-expansion 1.1.16`
- `brace-expansion 2.1.2`

Source: https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
