Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. brace-expansion
  4. ›
  5. CVE-2026-13149

CVE-2026-13149: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

July 20, 2026

brace-expansion’s expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node’s single-threaded event loop, one small input can fully stall a worker/process.

In expand_, post is computed unconditionally at the top of the function, before the early-return branches that don’t use it:

const post = m.post.length ? expand_(m.post, max, false) : [''];   // always recurses
...
if (!isSequence && !isOptions) {
if (m.post.match(/,(?!,).*\}/)) {
str = m.pre + '{' + m.body + escClose + m.post;
return expand_(str, max, true); // restart — `post` discarded
}
return [str];
}

For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but expand_ has already recursed into post over the entire remaining tail, only to throw the result away. Each level therefore spawns two recursive expansions over essentially the same remaining work: T(n) = 2·T(n−1) ⇒ O(2ⁿ).

The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.

Measured on 5.0.6:

groups (n)input bytestime
2060130 ms
24721.9 s
26787.8 s
30 (PoC)90~2 min

References

  • github.com/advisories/GHSA-3jxr-9vmj-r5cp
  • github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265
  • github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754
  • github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95
  • github.com/juliangruber/brace-expansion/pull/122
  • github.com/juliangruber/brace-expansion/pull/123
  • github.com/juliangruber/brace-expansion/releases/tag/v1.1.16
  • github.com/juliangruber/brace-expansion/releases/tag/v2.1.2
  • github.com/juliangruber/brace-expansion/releases/tag/v5.0.7
  • github.com/juliangruber/brace-expansion/security/advisories/GHSA-3jxr-9vmj-r5cp
  • nvd.nist.gov/vuln/detail/CVE-2026-13149
  • www.npmjs.com/package/brace-expansion

Code Behaviors & Features

Detect and mitigate CVE-2026-13149 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.1.16, all versions starting from 2.0.0 before 2.1.2, all versions starting from 3.0.0 before 5.0.7

Fixed versions

  • 1.1.16
  • 2.1.2
  • 5.0.7

Solution

Upgrade to versions 1.1.16, 2.1.2, 5.0.7 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-407: Inefficient Algorithmic Complexity

Source file

npm/brace-expansion/CVE-2026-13149.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:19:16 +0000.