PT-2026-41726 · Npm+1 · Brace-Expansion+1

·

CVE-2026-45149

·

Published

2026-05-18

·

Updated

2026-06-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions brace-expansion (affected versions not specified)
Description A Denial of Service (DoS) issue exists where the max option is applied too late during the expansion of large numeric ranges. For example, expanding a range like {1..10000000} causes the sequence generation loop to create all intermediate elements before applying the limit. This results in excessive memory allocation and processing time, even when a small max value is specified.
Recommendations Ensure the string to be expanded does not contain more values than the desired max item count.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45149
ECHO-B5C0-4020-9633
GHSA-JXXR-4GWJ-5JF2
RHSA-2026:22380
RHSA-2026:22934
RHSA-2026:24069
RHSA-2026:7378
RHSA-2026:7387
RHSA-2026:7634
RHSA-2026:7655
RHSA-2026:9455

Affected Products

Confluence
Brace-Expansion