CVE-2026-13149

NameCVE-2026-13149
Descriptionbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141325

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-brace-expansion (PTS)bullseye2.0.0-1vulnerable
bookworm2.0.1-2vulnerable
trixie2.0.1+~1.1.0-2vulnerable
forky, sid2.0.3+~1.1.2-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-brace-expansionsource(unstable)(unfixed)1141325

Notes

[trixie] - node-brace-expansion <no-dsa> (Minor issue)
[bookworm] - node-brace-expansion <postponed> (Minor issue)
[bullseye] - node-brace-expansion <postponed> (Minor issue)
https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754

Search for package or bug name: Reporting problems