GHSA-jxxr-4gwj-5jf2

    Dashboard / Vulnerabilities / GHSA-jxxr-4gwj-5jf2

    GHSA-jxxr-4gwj-5jf2

    Published: 18 May 2026Last Modified: 10 Sept 2026

    Summary: brace-expansion: Large numeric range defeats documented `max` DoS protection

    Details: The `max` option was being applied too late: When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process still allocates `~505 MB` and spends `~800ms` building the full intermediate array. ### Workaround Ensure the string to be expanded doesn't contain more values than the desired `max` item count.

    Affected packages

    Package

    Name: brace-expansion

    Purl: pkg:npm/brace-expansion

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.0.0
    Fixed -5.0.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-jxxr-4gwj-5jf2 | CVE-DB