Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
2.25.1 had one unnoted security vulnerability fixed:
CVE-2026-13149
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
https://github.com/advisories/GHSA-3jxr-9vmj-r5cp
Post summary
An advisory announces that the DoS vulnerability CVE‑2026‑13149 in brace‑expansion for version 2.25.1 has been fixed, with patch details available via the linked GitHub advisory.
🚨 HIGH - brace-expansion expand() algorithmic complexity DoS (CVE-2026-13149)
CVE-2026-13149 is a denial-of-service vulnerability in the brace-expansion package through 5.0.6, specifically in the expand() function when handling consecutive non-expanding '{}' brace groups. The root cause is exponential-time complexity (algorithmic complexity / uncontrolled recursion work) triggered by pathological input patterns, and the max option doesn’t mitigate it because it caps output size, not the computation required. An attacker can exploit this by supplying a crafted string to any code path that calls expand() (directly or via dependent tooling) to force worst-case processing, typically requiring only the ability to influence input. Successful exploitation can cause severe CPU exhaustion and event-loop blocking, leading to application unresponsiveness and service-level denial of service.
👉 Affected: brace-expansion <= 5.0.6 | Upgrade to No fix yet — treat as suspicious
Post summary
A tweet announces the high‑severity DoS vulnerability CVE‑2026‑13149 in brace‑expansion, outlining its algorithmic complexity trigger and impact, with no patch available yet and no active exploitation reported.