CyberRota Analysis
AI-GeneratedThe brace-expansion library is vulnerable to a denial-of-service condition due to uncontrolled recursion when processing deeply nested brace groups, which can lead to native stack exhaustion and terminate the Node.js process. This issue affects versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, and should be prioritized by developers and system administrators using these versions in applications that handle untrusted input. Immediate updates to the patched versions are recommended to mitigate potential service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.