Skip to content

CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) - #1167

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-api/brace-expansion-1.1.21
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-api/brace-expansion-1.1.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.18 to 1.1.21 in openam-ui/openam-ui-api (package-lock.json only), clearing Dependabot alert #343 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #341 and #342. This is the last of the three lock files: #1149 took openam-ui-ria from 1.1.18 to 1.1.21 and #1159 took openam-ui-js-sdk from 5.0.9 to 5.0.12 for the same three advisories.

Advisories

CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 1.1.19) — Uncontrolled recursion (CWE-674) in parseCommaParts(). The parser recursed once per comma-separated brace group, so expand('{' + '{a},'.repeat(7000) + 'b}') (~29 KB) overflows the native stack; a second vector spreads one huge array through push.apply and overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, so max / maxLength do not help. 1.1.19 rewrites the function as a loop and appends element by element.

CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 1.1.20) — Uncontrolled recursion (CWE-674) in expand_() on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257) never covered: '{a,'.repeat(4000) + 'z' + '}'.repeat(4000) (~15.6 KB) or '{'.repeat(3200) + 'a,b' + '}'.repeat(3200) (~6.25 KB) exhausts the stack. 1.1.20 threads a maxDepth bound through expand_(); past it a group is returned literally instead of throwing.

CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 1.1.21) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible {a},b} rewrite: every literal } costs a rescan of the whole (and growing) string, so '{a}' + '}'.repeat(n) + ',z}' is quadratic in n — 128 KB of input blocks the event loop for ~28 s. 1.1.21 bounds the number of rewrite passes.

Severity Affected (1.x line) Fixed in
GHSA-6j4f-fj2g-mc7p High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) < 1.1.19 1.1.19
GHSA-qhr7-859c-m2p7 High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) < 1.1.20 1.1.20
GHSA-q2hr-2g5m-vwhr Medium — CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) < 1.1.21 1.1.21

All three are availability-only: no code execution, no data exposure.

Impact on OpenAM

None at runtime, none in practice in the build. brace-expansion is a transitive development dependency of openam-ui-api (dev: true): the single copy in the lock file is pulled in by minimatch 3.1.5, which grunt 1.6.2 requires directly and through glob 7.1.7. No OpenAM source imports minimatch or brace-expansion, and neither ends up in the WAR — the module ships only the swagger-ui-dist files and src/main/resources that Grunt copies into target/www.

The Maven build runs npm run build:production → grunt build:prod, i.e. the two copy tasks in Gruntfile.js. Every pattern they expand (swagger-ui-bundle.js, swagger-ui-standalone-preset.js, swagger-ui.css, **) is written in that file, never taken from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.

Change

The node_modules/brace-expansion entry in openam-ui/openam-ui-api/package-lock.json: 1.1.18 → 1.1.21 (version, resolved, integrity). package.json is untouched — minimatch@3.1.5 asks for brace-expansion@^1.1.7, which 1.1.21 satisfies. No code or behaviour change.

Verified:

  • the lock file integrity matches npm view brace-expansion@1.1.21 dist.integrity
  • node_modules/brace-expansion is the only brace-expansion entry in this lock file

With this merged, no lock file in the repository resolves a vulnerable brace-expansion: openam-ui-ria is at 1.1.21 and openam-ui-js-sdk at 5.0.12.

References

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 11, 2026
@vharseko vharseko changed the title Bump brace-expansion from 1.1.18 to 1.1.21 in /openam-ui/openam-ui-api CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) Oct 11, 2026
@vharseko vharseko added the security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF) label Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant