Skip to content

CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) - #1149

Merged
vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/brace-expansion-1.1.21
Sep 30, 2026
Merged

vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/brace-expansion-1.1.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.18 to 1.1.21 in openam-ui/openam-ui-ria (package-lock.json only), clearing Dependabot alert #352 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #350 and #351.

Advisories

CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 1.1.19) — Uncontrolled recursion (CWE-674) in parseCommaParts(). The parser recursed once per comma-separated brace group, so expand('{' + '{a},'.repeat(7000) + 'b}') (~29 KB) overflows the native stack; a second vector spreads one huge array through push.apply and overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, so max / maxLength do not help. 1.1.19 rewrites the function as a loop and appends element by element.

CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 1.1.20) — Uncontrolled recursion (CWE-674) in expand_() on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257) never covered: '{a,'.repeat(4000) + 'z' + '}'.repeat(4000) (~15.6 KB) or '{'.repeat(3200) + 'a,b' + '}'.repeat(3200) (~6.25 KB) exhausts the stack. 1.1.20 threads a maxDepth bound through expand_(); past it a group is returned literally instead of throwing.

CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 1.1.21) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible {a},b} rewrite: every literal } costs a rescan of the whole (and growing) string, so '{a}' + '}'.repeat(n) + ',z}' is quadratic in n — 128 KB of input blocks the event loop for ~28 s. 1.1.21 bounds the number of rewrite passes.

Severity Affected (1.x line) Fixed in
GHSA-6j4f-fj2g-mc7p High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) < 1.1.19 1.1.19
GHSA-qhr7-859c-m2p7 High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) < 1.1.20 1.1.20
GHSA-q2hr-2g5m-vwhr Medium — CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) < 1.1.21 1.1.21

All three are availability-only: no code execution, no data exposure.

Impact on OpenAM

None at runtime, none in practice in the build. brace-expansion is a transitive development dependency of openam-ui-ria (dev: true): the single copy in the lock file is pulled in by minimatch 3.1.5, which the overrides block forces onto grunt, glob, globule, karma and mocha. No OpenAM source imports minimatch or brace-expansion, and neither ends up in the RIA bundle or the WAR. The patterns those tools expand come from the repository itself (Gruntfile.js and the files list in karma.conf.js; mocha runs inside karma, not through its CLI), never from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.

Change

The node_modules/brace-expansion entry in openam-ui/openam-ui-ria/package-lock.json: 1.1.18 → 1.1.21 (version, resolved, integrity). package.json is untouched — minimatch@^3.1.5 asks for brace-expansion@^1.1.7, which 1.1.21 satisfies. No code or behaviour change.

Verified:

  • the lock file integrity matches npm view brace-expansion@1.1.21 dist.integrity

Not covered:

References

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 30, 2026
@vharseko vharseko changed the title Bump brace-expansion from 1.1.18 to 1.1.21 in /openam-ui/openam-ui-ria CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) Sep 30, 2026
@vharseko
vharseko merged commit ad1aa22 into master Sep 30, 2026
16 checks passed
@vharseko
vharseko deleted the dependabot/npm_and_yarn/openam-ui/openam-ui-ria/brace-expansion-1.1.21 branch September 30, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant