Repository navigation
CVE-2026-102276 CVE-2026-102277 CVE-2026-102278 brace-expansion: Stack-exhaustion and quadratic-time DoS in brace parsing (1.1.18 -> 1.1.21) - #1167
Open
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.21 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps
brace-expansionfrom 1.1.18 to 1.1.21 inopenam-ui/openam-ui-api(package-lock.jsononly), clearing Dependabot alert #343 for this lock file; the same bump also fixes the two advisories behind the auto-dismissed alerts #341 and #342. This is the last of the three lock files: #1149 tookopenam-ui-riafrom 1.1.18 to 1.1.21 and #1159 tookopenam-ui-js-sdkfrom 5.0.9 to 5.0.12 for the same three advisories.Advisories
CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p (fixed in 1.1.19) — Uncontrolled recursion (CWE-674) in
parseCommaParts(). The parser recursed once per comma-separated brace group, soexpand('{' + '{a},'.repeat(7000) + 'b}')(~29 KB) overflows the native stack; a second vector spreads one huge array throughpush.applyand overflows the stack at recursion depth 1 (~249 KB). Both crash during parsing, somax/maxLengthdo not help. 1.1.19 rewrites the function as a loop and appends element by element.CVE-2026-102278 / GHSA-qhr7-859c-m2p7 (fixed in 1.1.20) — Uncontrolled recursion (CWE-674) in
expand_()on brace nesting, which the earlier tail-recursion fix (CVE-2026-14257) never covered:'{a,'.repeat(4000) + 'z' + '}'.repeat(4000)(~15.6 KB) or'{'.repeat(3200) + 'a,b' + '}'.repeat(3200)(~6.25 KB) exhausts the stack. 1.1.20 threads amaxDepthbound throughexpand_(); past it a group is returned literally instead of throwing.CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr (fixed in 1.1.21) — Inefficient algorithmic complexity (CWE-407) in the Bash-compatible
{a},b}rewrite: every literal}costs a rescan of the whole (and growing) string, so'{a}' + '}'.repeat(n) + ',z}'is quadratic inn— 128 KB of input blocks the event loop for ~28 s. 1.1.21 bounds the number of rewrite passes.AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)All three are availability-only: no code execution, no data exposure.
Impact on OpenAM
None at runtime, none in practice in the build.
brace-expansionis a transitive development dependency ofopenam-ui-api(dev: true): the single copy in the lock file is pulled in byminimatch3.1.5, whichgrunt1.6.2 requires directly and throughglob7.1.7. No OpenAM source importsminimatchorbrace-expansion, and neither ends up in the WAR — the module ships only theswagger-ui-distfiles andsrc/main/resourcesthat Grunt copies intotarget/www.The Maven build runs
npm run build:production→grunt build:prod, i.e. the twocopytasks inGruntfile.js. Every pattern they expand (swagger-ui-bundle.js,swagger-ui-standalone-preset.js,swagger-ui.css,**) is written in that file, never taken from outside input, so the untrusted glob pattern every advisory requires does not exist here. The bump takes the development toolchain out of the vulnerable range.Change
The
node_modules/brace-expansionentry inopenam-ui/openam-ui-api/package-lock.json: 1.1.18 → 1.1.21 (version,resolved,integrity).package.jsonis untouched —minimatch@3.1.5asks forbrace-expansion@^1.1.7, which 1.1.21 satisfies. No code or behaviour change.Verified:
integritymatchesnpm view brace-expansion@1.1.21 dist.integritynode_modules/brace-expansionis the onlybrace-expansionentry in this lock fileWith this merged, no lock file in the repository resolves a vulnerable
brace-expansion:openam-ui-riais at 1.1.21 andopenam-ui-js-sdkat 5.0.12.References