Description
@isaacs/brace-expansion is vulnerable to a Denial of Service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously.
Recommendation
Update the @isaacs/brace-expansion package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.0.0
- Patched version(s): 5.0.1
References
Related Issues
- @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue - CVE-2026-8769
- DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption - CVE-2026-10691
- Uncontrolled Resource Consumption in ansi-html - CVE-2021-23424
- graphql Uncontrolled Resource Consumption vulnerability - CVE-2023-26144
You might also like:
- Tags:
- npm
- @isaacs/brace-expansion
Anything's wrong? Let us know Last updated on February 05, 2026


