Listen to this Post
CVE-2026-102277 is a quadratic-time algorithmic complexity vulnerability in the npm `brace-expansion` package’s `expand()` function. The flaw is triggered by crafted input shaped like `{a},b}` followed by many trailing `}` characters. Bash preserves a historical quirk where a brace group followed by a comma set still expands, so the parser implements this by rewriting the string and restarting the scan. Each rewrite pass absorbs exactly one `}` and then rescans the entire string from the beginning. Therefore, `n` trailing braces cost `n` full passes, producing `O(n²)` time complexity. Instrumentation confirms the rewrite branch runs `n + 1` times. A second multiplier worsens the problem: the rewrite replaces the closing `}` of the group with an internal `escClose` sentinel of roughly 25 characters ('\0CLOSE' + Math.random() + '\0'). The working string therefore grows by about 25 characters on every pass. For example, an 8,006-byte input becomes 208,006 bytes after processing, inflating memory roughly 26×. This makes the vulnerability partly a memory-pressure issue as well as a CPU one. The `max` and `maxLength` options do not help because the cost occurs during parsing, before the result set exists. The payload yields only two results regardless of input size, so neither bound is ever reached. An application that passes an untrusted pattern to expand(), directly or through `minimatch` or glob, can have its event loop blocked for tens of seconds by a payload well under minimatch’s 65,536-character cap. For a single-threaded Node.js server, this is a full stall, not merely a slow request. The process recovers once expansion completes, so the impact is degraded availability rather than a crash. Verified affected versions include 1.1.18, 2.1.4, 3.0.6, and 5.0.9, all within a few percent of each other at roughly 460–490 ms for n=16,000. The patch introduces an iteration bound on the rewrite loop; past the cap, the remaining string is treated as non-expanding and returned literally. This bounds the number of passes, though worst-case work remains proportional to cap × input length.
DailyCVE Form:
Platform: brace-expansion
Version: <1.1.21, 2.1.7, 3.0.9, 5.0.12
Vulnerability: Quadratic complexity
Severity: Medium (5.3)
date: 2026-09-28
Prediction: 2026-09-28
What Undercode Say:
Check installed brace-expansion version
npm ls brace-expansion
Reproduce the quadratic blowup
node -e "
const { expand } = require('brace-expansion');
const build = n => '{a}' + '}'.repeat(n) + ',z}';
for (const n of [8000, 16000, 32000, 64000, 128000]) {
const t = Date.now();
expand(build(n));
console.log(n, Date.now() - t + 'ms');
}
"
Exploit: (Educational Purposes!)
const { expand } = require('brace-expansion');
// Craft a payload that forces n full rescans
const payload = '{a}' + '}'.repeat(128000) + ',z}';
// This blocks the event loop for ~27.7 seconds
expand(payload);
Protection: from this CVE
- Upgrade `brace-expansion` to version 1.1.21, 2.1.7, 3.0.9, or 5.0.12 or later.
- Avoid passing untrusted input directly to `expand()` or to
minimatch/globbrace patterns. - Enforce strict input length limits before pattern processing.
- Apply request timeouts and rate limiting to limit the blast radius of a single malicious request.
Impact:
Event loop blocking for tens of seconds, causing full service stall on single-threaded Node.js servers. Degraded availability rather than a crash. The process recovers once expansion completes, but dependent systems may experience cascading failures during the stall.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

