{"id":"AZL-105078","summary":"CVE-2026-102278 affecting package js-jquery 3.5.0-4","details":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.","modified":"2026-10-02T05:31:52Z","published":"2026-09-28T21:17:16Z","upstream":["CVE-2026-102278"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278"}],"affected":[{"package":{"name":"js-jquery","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/js-jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.5.0-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105078.json"}}],"schema_version":"1.9.0"}