Overview
A flaw was found in the brace-expansion library. The expand() function does not apply maxLength when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop, resulting in a denial of service. This issue is due to an incomplete mitigation of CVE-2026-14257.
Vendor advisories
- RHSA-2026:64817 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-08 · advisory
- RHSA-2026:61374 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-31 · advisory
- RHSA-2026:55541 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-17 · advisory
- RHSA-2026:52841 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-10 · advisory
- RHSA-2026:58819 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-24 · advisory
- RHSA-2026:54530 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-13 · advisory
- RHSA-2026:54371 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-12 · advisory
- RHSA-2026:62416 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-02 · advisory
- RHSA-2026:55601 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-17 · advisory
- RHSA-2026:55603 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-17 · advisory
- RHSA-2026:57590 · Red Hat · fixed in: Red Hat Enterprise Linux Extensions Channel (v. 10) · released 2026-08-20 · advisory
- Red Hat VEX · Important · affected: Cryostat 4, Exploit Intelligence, Migration Toolkit for Applications 8, Migration Toolkit for Containers, Node HealthCheck Operator, OpenShift Lightspeed, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, … · updated 2026-09-08 · vex
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — rated Important by Red Hat. Released 2026-08-03, updated 2026-09-08.
Affected:
- Cryostat 4
- Exploit Intelligence
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Ceph Storage 4
- Red Hat Connectivity Link 1
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Dev Spaces
- Red Hat OpenShift GitOps
- Red Hat Quay 3
- Red Hat Single Sign-On 7
- Red Hat Trusted Profile Analyzer
- Secrets Management Console for Red Hat OpenShift
- Self-service automation portal 2
Fixed:
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux Extensions Channel (v. 10)
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.1
- Red Hat Ansible Automation Platform 2.2
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Developer Hub 1.10
- Red Hat Discovery 2
- Red Hat Hardened Images
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Dev Spaces 3.30
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4
- Red Hat Quay 3.15
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19
No fix planned:
- Red Hat Ansible Automation Platform 2
- Red Hat Directory Server 11
- Red Hat Directory Server 12
- Red Hat Directory Server 13
- Red Hat Fuse 7
- Red Hat Hardened Images
- Red Hat Openshift Data Foundation 4
- Secrets Management Console for Red Hat OpenShift
- Red Hat Ceph Storage 4
- Cryostat 4
- Exploit Intelligence
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat AMQ Broker 7
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 3
- Red Hat Build of Podman Desktop
- Red Hat Connectivity Link 1
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Spaces
- Red Hat OpenShift GitOps
- Red Hat Quay 3
- Red Hat Single Sign-On 7
- Red Hat Trusted Profile Analyzer
- Self-service automation portal 2
Not affected:
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Developer Hub 1.10
- Red Hat Discovery 2
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:64817
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:61374
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:55541
Workarounds / mitigations:
- To mitigate this vulnerability, do not pass untrusted input to the expand() function.
Package advisory (CVE-2026-69152)
Affected packages:
brace-expansion < 1.1.18
brace-expansion >= 2.0.0, < 2.1.4
brace-expansion >= 3.0.0, < 3.0.6
brace-expansion >= 4.0.0, < 5.0.9
Patched in:
brace-expansion 1.1.18
brace-expansion 2.1.4
brace-expansion 3.0.6
brace-expansion 5.0.9
Source: https://github.com/advisories/GHSA-rgw5-rvv9-x895