Skip to content

CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (5.0.9 -> 5.0.12) - #1159

Merged
vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-js-sdk/brace-expansion-5.0.12
Oct 1, 2026
Merged

vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-js-sdk/brace-expansion-5.0.12

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 5.0.9 to 5.0.12 in openam-ui/openam-ui-js-sdk (package-lock.json only), clearing Dependabot alert #346 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #344 and #345. This is the 5.x counterpart of #1149, which took openam-ui-ria from 1.1.18 to 1.1.21 for the same three advisories.

Advisories

CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 5.0.10) — Uncontrolled recursion (CWE-674) in parseCommaParts(). The parser recursed once per comma-separated brace group, so expand('{' + '{a},'.repeat(7000) + 'b}') (~29 KB) overflows the native stack; a second vector spreads one huge array through push.apply and overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, so max / maxLength do not help. 5.0.10 rewrites the function as a loop and appends element by element.

CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 5.0.11) — Uncontrolled recursion (CWE-674) in expand_() on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257, 5.0.8) never covered: '{a,'.repeat(4000) + 'z' + '}'.repeat(4000) (~15.6 KB) or '{'.repeat(3200) + 'a,b' + '}'.repeat(3200) (~6.25 KB) exhausts the stack. 5.0.11 threads a maxDepth bound through expand_(); past it a group is returned literally instead of throwing.

CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 5.0.12) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible {a},b} rewrite: every literal } costs a rescan of the whole (and growing) string, so '{a}' + '}'.repeat(n) + ',z}' is quadratic in n — 128 KB of input blocks the event loop for ~28 s. 5.0.12 bounds the number of rewrite passes.

The advisories name 5.0.9 explicitly among the verified-affected releases; none of the three is a regression from the earlier 5.0.x fixes.

Severity Affected (5.x line) Fixed in
GHSA-6j4f-fj2g-mc7p High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) >= 4.0.0, < 5.0.10 5.0.10
GHSA-qhr7-859c-m2p7 High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) >= 4.0.0, < 5.0.11 5.0.11
GHSA-q2hr-2g5m-vwhr Medium — CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) >= 4.0.0, < 5.0.12 5.0.12

All three are availability-only: no code execution, no data exposure.

Impact on OpenAM

None at runtime, none in practice in the build. brace-expansion is a transitive development dependency of openam-ui-js-sdk (dev: true): the single copy in the lock file is shared by the top-level minimatch 10.2.5 (required by eslint, @eslint/config-array and @typescript-eslint/typescript-estree) and the copy of minimatch 10.2.3 nested under @microsoft/api-extractor. No OpenAM source imports minimatch or brace-expansion, and neither ends up in the SDK bundle (target/lib, target/app) or the WAR — the runtime dependencies are only react, react-dom and react-router.

Of these tools, the Maven build reaches only @microsoft/api-extractor: npm run build (bound to compile) runs build:lib, where vite-plugin-dts with bundleTypes: true drives it to roll up the type declarations. eslint runs only through the manual npm run lint script; npm run test:run (bound to test) is plain vitest. Every pattern these tools expand comes from the repository itself (vite.lib.config.ts, tsconfig.lib.json, eslint.config.js), never from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.

Change

The node_modules/brace-expansion entry in openam-ui/openam-ui-js-sdk/package-lock.json: 5.0.9 → 5.0.12 (version, resolved, integrity). package.json is untouched — minimatch@10.2.5 asks for brace-expansion@^5.0.5 and minimatch@10.2.3 for ^5.0.2, both satisfied by 5.0.12. No code or behaviour change.

Verified:

  • the lock file integrity matches npm view brace-expansion@5.0.12 dist.integrity
  • node_modules/brace-expansion is the only brace-expansion entry in this lock file

Not covered:

References

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.9 to 5.0.12.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@vharseko vharseko changed the title Bump brace-expansion from 5.0.9 to 5.0.12 in /openam-ui/openam-ui-js-sdk CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (5.0.9 -> 5.0.12) Oct 1, 2026
@vharseko
vharseko merged commit d371abc into master Oct 1, 2026
14 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/openam-ui/openam-ui-js-sdk/brace-expansion-5.0.12 branch October 1, 2026 12:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant