CVE-2026-13149Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-30: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-30: 106-3007-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-301
Disclosure1
Full discourse3 posts
  • AT Products LLC@ATProductsLLC
    Disclosure

    2.25.1 had one unnoted security vulnerability fixed: CVE-2026-13149 brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups https://github.com/advisories/GHSA-3jxr-9vmj-r5cp

    Post summary

    An advisory announces that the DoS vulnerability CVE‑2026‑13149 in brace‑expansion for version 2.25.1 has been fixed, with patch details available via the linked GitHub advisory.

    0000061
    106 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - brace-expansion expand() algorithmic complexity DoS (CVE-2026-13149) CVE-2026-13149 is a denial-of-service vulnerability in the brace-expansion package through 5.0.6, specifically in the expand() function when handling consecutive non-expanding '{}' brace groups. The root cause is exponential-time complexity (algorithmic complexity / uncontrolled recursion work) triggered by pathological input patterns, and the max option doesn’t mitigate it because it caps output size, not the computation required. An attacker can exploit this by supplying a crafted string to any code path that calls expand() (directly or via dependent tooling) to force worst-case processing, typically requiring only the ability to influence input. Successful exploitation can cause severe CPU exhaustion and event-loop blocking, leading to application unresponsiveness and service-level denial of service. 👉 Affected: brace-expansion <= 5.0.6 | Upgrade to No fix yet — treat as suspicious

    Post summary

    A tweet announces the high‑severity DoS vulnerability CVE‑2026‑13149 in brace‑expansion, outlining its algorithmic complexity trigger and impact, with no patch available yet and no active exploitation reported.

    0000068
    232 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13149 Denial of Service Vulnerability in Brace-Expansion Through 5.0.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13149

    Post summary

    A new Denial of Service vulnerability, CVE-2026-13149, has been disclosed affecting Brace-Expansion versions up to 5.0.6.

    00000102
    4.1K followersView on X

Explore more