CVE-2026-25547Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-04: 2Mentions · 2026-03-19: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-02-04: 202-0403-19
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure1Patch1
2026-03-191
Patch1
Full discourse3 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25547: Uncontrolled Resource Consumptio... Exponential resource exhaustion in @isaacs/brace-expansion <5.0.1 lets attackers crash Node.js processes with minimal i... https://zerodaysignal.com/vulnerability/CVE-2026-25547 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑25547 is a newly disclosed vulnerability in the isaacs/brace-expansion package that causes exponential resource exhaustion, allowing attackers to crash Node.js processes.

    0101075
    132 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-25547 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/395 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The CVE‑2026‑25547 vulnerability has been eliminated from the latest AWS Lambda base images, indicating a patch or removal—no active exploitation or PoC is discussed.

    0000043
    32 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (… https://www.cve.org/CVERecord?id=CVE-2026-25547

    Post summary

    CVE-2026-25547 is a denial‑of‑service flaw in @isaacs/brace-expansion before version 5.0.1, fixed in that release.

    00000183
    56.5K followersView on X

Explore more