GHSA-vfj7-8cjw-p6xm

Suggest an improvement
Source
https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vfj7-8cjw-p6xm/GHSA-vfj7-8cjw-p6xm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vfj7-8cjw-p6xm
Aliases
Downstream
CGA (205)
Published
2026-09-18T18:31:41Z
Modified
2026-10-02T22:45:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
Details

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

Database specific
{
    "cwe_ids":  [
        "CWE-674"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-02T22:36:33Z",
    "nvd_published_at":  "2026-09-18T16:17:15Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / braces

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vfj7-8cjw-p6xm/GHSA-vfj7-8cjw-p6xm.json"