Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jxxr-4gwj-5jf2 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
Tue, 16 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 03 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:juliangruber:brace-expansion:*:*:*:*:*:node.js:*:* |
Mon, 01 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Juliangruber
Juliangruber brace-expansion |
|
| Vendors & Products |
Juliangruber
Juliangruber brace-expansion |
Fri, 29 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6. | |
| Title | brace-expansion: Large numeric range defeats documented `max` DoS protection | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T16:44:23.371Z
Reserved: 2026-05-08T20:44:38.964Z
Link: CVE-2026-45149
Updated: 2026-06-01T16:44:17.118Z
Status : Analyzed
Published: 2026-05-29T20:16:25.550
Modified: 2026-06-12T18:38:01.507
Link: CVE-2026-45149
OpenCVE Enrichment
Updated: 2026-06-18T04:00:15Z
Github GHSA