---
id: CVE-2026-14257
title: >-
  brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in
  expand() function (CVE-2026-14257)
summary: >-
  A flaw was found in brace-expansion. A remote attacker can exploit this
  vulnerability by providing specially crafted input to the expand() function,
  which can lead to excessive memory consumption. This can cause a denial of
  service (DoS) b…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
  - CWE-400
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream (v. 8)
affected:
  - exploit_intelligence
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_containers
  - openshift_lightspeed
  - openshift_pipelines
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - hardened_images
  - openshift_data_foundation 4
  - openshift_gitops
  - single_sign_on 7
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_extensions_channel_v_10
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - discovery 2
  - openshift_container_platform 4.20
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_extensions_channel_v_10
  - ansible_automation_platform 2.1
  - ansible_automation_platform 2.2
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - discovery 2
  - hardened_images
  - openshift_container_platform 4.20
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - openshift_service_mesh 3.3
  - openshift_service_mesh 3.4
published: '2026-07-23'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:25:16+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14257.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14257.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-14257'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2506433'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-14257'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14257'
  - url: 'https://github.com/juliangruber/brace-expansion'
  - url: >-
      https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5
  - url: 'https://www.npmjs.com/package/brace-expansion'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64817'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55541'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58819'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54530'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54371'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62416'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55601'
  - url: 'https://access.redhat.com/errata/RHSA-2026:55603'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57590'
  - url: 'https://access.redhat.com/errata/RHSA-2026:56338'
  - url: 'https://access.redhat.com/errata/RHSA-2026:56357'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66003'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59159'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59155'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54760'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50290'
  - url: 'https://access.redhat.com/errata/RHSA-2026:45381'
  - url: 'https://access.redhat.com/errata/RHSA-2026:45784'
  - url: 'https://access.redhat.com/errata/RHSA-2026:45360'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60447'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57545'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60478'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57801'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57367'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57365'
  - url: >-
      https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg
  - url: 'https://github.com/advisories/GHSA-mh99-v99m-4gvg'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00643
epssPercentile: 0.48619
aliases:
  - GHSA-mh99-v99m-4gvg
ecosystem: npm
ingestedAt: '2026-07-24T22:40:26.857Z'
---

## Overview

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) by crashing the application due to an out-of-memory error.

## Vendor advisories

- **RHSA-2026:64817** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64817)
- **RHSA-2026:55541** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55541)
- **RHSA-2026:58819** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58819)
- **RHSA-2026:54530** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54530)
- **RHSA-2026:54371** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54371)
- **RHSA-2026:62416** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62416)
- **RHSA-2026:55601** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55601)
- **RHSA-2026:55603** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55603)
- **RHSA-2026:57590** · Red Hat · fixed in: Red Hat Enterprise Linux Extensions Channel (v. 10) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57590)
- **RHSA-2026:56338** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.1 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56338)
- **RHSA-2026:56357** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.2 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56357)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Migration Toolkit for Containers, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, … · no fix planned: OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Hardened Images, Red Hat Openshift Data Foundation 4, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14257.json)

**brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function** — rated Important by Red Hat. Released 2026-07-23, updated 2026-09-09.

Affected:

- Exploit Intelligence
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat Single Sign-On 7

Fixed:

- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat Ansible Automation Platform 2.1
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Discovery 2
- Red Hat Hardened Images
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4

No fix planned:

- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4
- Exploit Intelligence
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift GitOps
- Red Hat Single Sign-On 7

Not affected:

- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Discovery 2
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4
- Cryostat 4

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:64817
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:55541
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:58819

Workarounds / mitigations:

- Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion.

Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output.

As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as…

## Package advisory (CVE-2026-14257)

Affected packages:

- `brace-expansion <= 5.0.7`

Patched in:

- `brace-expansion 5.0.8`

Source: https://github.com/advisories/GHSA-mh99-v99m-4gvg
