CVE-2026-93687

NameCVE-2026-93687
Descriptionbraces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148400

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-braces (PTS)bookworm3.0.2+~3.0.1-1vulnerable
forky, sid, trixie3.0.3+~3.0.5-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-bracessource(unstable)(unfixed)1148400

Notes

[trixie] - node-braces <no-dsa> (Minor issue)
[bookworm] - node-braces <postponed> (Minor issue, DoS)
https://github.com/micromatch/braces/issues/70

Search for package or bug name: Reporting problems