chore(deps): update dependency brace-expansion@<1.1.13 to v1.1.16 [security] - #6385
Merged
renovate[bot] merged 1 commit intoJul 27, 2026
Merged
Conversation
|
✅ Meticulous spotted 0 visual differences across 289 screens tested: view results. Meticulous evaluated ~4 hours of user flows against your PR. Expected differences? Click here. Last updated for commit |
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 26, 2026 05:14
5410568 to
62281ab
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 26, 2026 08:41
62281ab to
c217e5c
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 26, 2026 12:45
c217e5c to
31f8e0e
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 26, 2026 18:20
31f8e0e to
c3fa901
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 26, 2026 20:41
c3fa901 to
b91464d
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 27, 2026 00:44
b91464d to
475e568
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 27, 2026 04:46
475e568 to
c2db7f1
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 27, 2026 10:19
c2db7f1 to
78350be
Compare
renovate
Bot
force-pushed
the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
from
July 27, 2026 13:08
78350be to
763b568
Compare
renovate
Bot
deleted the
renovate/npm-brace-expansion-1.1.13-vulnerability
branch
July 27, 2026 18:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.1.13→1.1.16Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp
More information
Details
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In
expand_,postis computed unconditionally at the top of the function, before the early-return branches that don't use it:For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but
expand_has already recursed into post over the entire remaining tail, only to throw the result away.Each level therefore spawns two recursive expansions over essentially the same remaining work:
T(n) = 2·T(n−1) ⇒ O(2ⁿ).The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
Proof of concept
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:AmberReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion@<1.1.13)
v1.1.16Compare Source
v1.1.15Compare Source
0b09384v1.1.14Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.