{"id":"GHSA-jxxr-4gwj-5jf2","summary":"brace-expansion: Large numeric range defeats documented `max` DoS protection","details":"The `max` option was being applied too late:\n\nWhen expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process still allocates `~505 MB` and spends `~800ms` building the full intermediate array.\n\n### Workaround\n\nEnsure the string to be expanded doesn't contain more values than the desired `max` item count.","aliases":["CVE-2026-45149"],"modified":"2026-09-10T03:51:06.302870102Z","published":"2026-05-18T16:22:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-18T16:22:01Z","nvd_published_at":"2026-05-29T20:16:25Z","cwe_ids":["CWE-400"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45149"},{"type":"WEB","url":"https://github.com/juliangruber/brace-expansion/commit/c0b095bdc52bc4c36dc88deddbadabc49f8371e5"},{"type":"PACKAGE","url":"https://github.com/juliangruber/brace-expansion"}],"affected":[{"package":{"name":"brace-expansion","ecosystem":"npm","purl":"pkg:npm/brace-expansion"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.0.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jxxr-4gwj-5jf2/GHSA-jxxr-4gwj-5jf2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}