brace-expansion vulnerabilities
CVEs whose affected-version data names the brace-expansion package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-102278High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and si…
CVE-2026-102277Medium· 5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by r…
CVE-2026-102276High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recu…