CVE-2026-45149

NameCVE-2026-45149
DescriptionThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1138576

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-brace-expansion (PTS)bullseye2.0.0-1vulnerable
bookworm2.0.1-2vulnerable
trixie2.0.1+~1.1.0-2vulnerable
forky, sid2.0.3+~1.1.2-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-brace-expansionsource(unstable)(unfixed)1138576

Notes

https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2
Fixed by: https://github.com/juliangruber/brace-expansion/commit/c0b095bdc52bc4c36dc88deddbadabc49f8371e5 (v5.0.6)

Search for package or bug name: Reporting problems