CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) - #1149
Merged
vharseko merged 1 commit intoSep 30, 2026
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.21 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
vharseko
approved these changes
Sep 30, 2026
vharseko
deleted the
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/brace-expansion-1.1.21
branch
September 30, 2026 15:49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps
brace-expansionfrom 1.1.18 to 1.1.21 inopenam-ui/openam-ui-ria(package-lock.jsononly), clearing Dependabot alert #352 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #350 and #351.Advisories
CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 1.1.19) — Uncontrolled recursion (CWE-674) in
parseCommaParts(). The parser recursed once per comma-separated brace group, soexpand('{' + '{a},'.repeat(7000) + 'b}')(~29 KB) overflows the native stack; a second vector spreads one huge array throughpush.applyand overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, somax/maxLengthdo not help. 1.1.19 rewrites the function as a loop and appends element by element.CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 1.1.20) — Uncontrolled recursion (CWE-674) in
expand_()on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257) never covered:'{a,'.repeat(4000) + 'z' + '}'.repeat(4000)(~15.6 KB) or'{'.repeat(3200) + 'a,b' + '}'.repeat(3200)(~6.25 KB) exhausts the stack. 1.1.20 threads amaxDepthbound throughexpand_(); past it a group is returned literally instead of throwing.CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 1.1.21) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible
{a},b}rewrite: every literal}costs a rescan of the whole (and growing) string, so'{a}' + '}'.repeat(n) + ',z}'is quadratic inn— 128 KB of input blocks the event loop for ~28 s. 1.1.21 bounds the number of rewrite passes.AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)All three are availability-only: no code execution, no data exposure.
Impact on OpenAM
None at runtime, none in practice in the build.
brace-expansionis a transitive development dependency ofopenam-ui-ria(dev: true): the single copy in the lock file is pulled in byminimatch3.1.5, which theoverridesblock forces ontogrunt,glob,globule,karmaandmocha. No OpenAM source importsminimatchorbrace-expansion, and neither ends up in the RIA bundle or the WAR. The patterns those tools expand come from the repository itself (Gruntfile.jsand thefileslist inkarma.conf.js; mocha runs inside karma, not through its CLI), never from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.Change
The
node_modules/brace-expansionentry inopenam-ui/openam-ui-ria/package-lock.json: 1.1.18 → 1.1.21 (version,resolved,integrity).package.jsonis untouched —minimatch@^3.1.5asks forbrace-expansion@^1.1.7, which 1.1.21 satisfies. No code or behaviour change.Verified:
integritymatchesnpm view brace-expansion@1.1.21 dist.integrityNot covered:
openam-ui/openam-ui-api/package-lock.jsonstill resolvesbrace-expansion1.1.18 (alerts Issue when trying to update Subjects within policy #341–update qrcode.js to 1.4.4 #343) and needs its own lock refresh to 1.1.21.openam-ui/openam-ui-js-sdk/package-lock.jsonresolves the 5.x line at 5.0.9 (alerts Compatibility #344–Submodules missing when cloning #346) and needs 5.0.12.References