CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (5.0.9 -> 5.0.12) - #1159
Merged
vharseko merged 1 commit intoOct 1, 2026
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.9 to 5.0.12. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.9...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
vharseko
approved these changes
Oct 1, 2026
dependabot
Bot
deleted the
dependabot/npm_and_yarn/openam-ui/openam-ui-js-sdk/brace-expansion-5.0.12
branch
October 1, 2026 12:49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps
brace-expansionfrom 5.0.9 to 5.0.12 inopenam-ui/openam-ui-js-sdk(package-lock.jsononly), clearing Dependabot alert #346 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #344 and #345. This is the 5.x counterpart of #1149, which tookopenam-ui-riafrom 1.1.18 to 1.1.21 for the same three advisories.Advisories
CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 5.0.10) — Uncontrolled recursion (CWE-674) in
parseCommaParts(). The parser recursed once per comma-separated brace group, soexpand('{' + '{a},'.repeat(7000) + 'b}')(~29 KB) overflows the native stack; a second vector spreads one huge array throughpush.applyand overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, somax/maxLengthdo not help. 5.0.10 rewrites the function as a loop and appends element by element.CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 5.0.11) — Uncontrolled recursion (CWE-674) in
expand_()on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257, 5.0.8) never covered:'{a,'.repeat(4000) + 'z' + '}'.repeat(4000)(~15.6 KB) or'{'.repeat(3200) + 'a,b' + '}'.repeat(3200)(~6.25 KB) exhausts the stack. 5.0.11 threads amaxDepthbound throughexpand_(); past it a group is returned literally instead of throwing.CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 5.0.12) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible
{a},b}rewrite: every literal}costs a rescan of the whole (and growing) string, so'{a}' + '}'.repeat(n) + ',z}'is quadratic inn— 128 KB of input blocks the event loop for ~28 s. 5.0.12 bounds the number of rewrite passes.The advisories name 5.0.9 explicitly among the verified-affected releases; none of the three is a regression from the earlier 5.0.x fixes.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)All three are availability-only: no code execution, no data exposure.
Impact on OpenAM
None at runtime, none in practice in the build.
brace-expansionis a transitive development dependency ofopenam-ui-js-sdk(dev: true): the single copy in the lock file is shared by the top-levelminimatch10.2.5 (required byeslint,@eslint/config-arrayand@typescript-eslint/typescript-estree) and the copy ofminimatch10.2.3 nested under@microsoft/api-extractor. No OpenAM source importsminimatchorbrace-expansion, and neither ends up in the SDK bundle (target/lib,target/app) or the WAR — the runtime dependencies are onlyreact,react-domandreact-router.Of these tools, the Maven build reaches only
@microsoft/api-extractor:npm run build(bound tocompile) runsbuild:lib, wherevite-plugin-dtswithbundleTypes: truedrives it to roll up the type declarations.eslintruns only through the manualnpm run lintscript;npm run test:run(bound totest) is plainvitest. Every pattern these tools expand comes from the repository itself (vite.lib.config.ts,tsconfig.lib.json,eslint.config.js), never from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.Change
The
node_modules/brace-expansionentry inopenam-ui/openam-ui-js-sdk/package-lock.json: 5.0.9 → 5.0.12 (version,resolved,integrity).package.jsonis untouched —minimatch@10.2.5asks forbrace-expansion@^5.0.5andminimatch@10.2.3for^5.0.2, both satisfied by 5.0.12. No code or behaviour change.Verified:
integritymatchesnpm view brace-expansion@5.0.12 dist.integritynode_modules/brace-expansionis the onlybrace-expansionentry in this lock fileNot covered:
openam-ui/openam-ui-api/package-lock.jsonstill resolvesbrace-expansion1.1.18 (alert update qrcode.js to 1.4.4 #343 open, Issue when trying to update Subjects within policy #341–ForgeRock OATH module not showing QR code for device setup due to old JavaScript library #342 auto-dismissed) and needs its own lock refresh to 1.1.21.References