chore(deps): update dependency brace-expansion@<1.1.16 to v5 [security] - autoclosed - #9294
chore(deps): update dependency brace-expansion@<1.1.16 to v5 [security] - autoclosed#9294renovate[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the dependency override for brace-expansion in package.json, likely to address a security/advisory constraint on older brace-expansion versions.
Changes:
- Changed the override for
brace-expansion@<1.1.16from^1.1.16to^5.0.0.
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
COMPARE TO
|
| Name | Diff |
|---|---|
| package.json | 📉 -1 Bytes |
| pnpm-lock.yaml | 📉 -918 Bytes |
2c9869e to
6aaaaaa
Compare
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
6aaaaaa to
375f435
Compare
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.0", |
375f435 to
d05f0ec
Compare
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
d05f0ec to
09ac91d
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
Comments suppressed due to low confidence (1)
package.json:56
- Overriding requests for
brace-expansion@<1.1.16to^5.0.0is a major-version jump and can break transitive consumers that expect the v1 API/behavior (especially older packages constraining to<1.1.16). If the intent is a security patch, consider keeping the override within the v1 line (e.g., pin to1.1.16) or, if a major bump is required, document why this is safe and prefer aligning with the existing v5 override you already have (e.g.,^5.0.8) to minimize version skew.
"brace-expansion@<1.1.16": "^5.0.0",
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.0", |
e018e5c to
24689fb
Compare
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
24689fb to
f5b3051
Compare
f5b3051 to
ea2d2f5
Compare
| "brace-expansion@<1.1.16": "^5.0.0", | ||
| "brace-expansion@>=2.0.0 <2.1.2": "^2.1.2", | ||
| "brace-expansion@>=4.0.0 <5.0.8": "^5.0.8", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
Comments suppressed due to low confidence (1)
package.json:56
- This override targets dependents that request
brace-expansionversions<1.1.16(v1.x range) but forces them to resolve to^5.0.0(a major-version jump). That can break transitive dependencies that relied on v1.x behavior/exports. If the goal is to remediate a v1.x vulnerability, consider pinning to1.1.16(within v1) instead, or adjust the selector to target ranges that are known-compatible with v5 (and document/validate compatibility).
"brace-expansion@<1.1.16": "^5.0.0",
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.0", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.0", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", |
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.0", |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
Suppressed comments (1)
package.json:58
- Overriding a
<1.1.16(v1) constraint to^5.0.0forces a major-version jump that may break transitive dependents expecting the v1 API/behavior. If the intent is to patch the vulnerable v1 range, prefer overriding to a patched v1 release (e.g.,1.1.16or^1.1.16) to stay within the same major. If you’ve validated that v5 is compatible for those consumers, consider aligning to a single v5 target (e.g.,^5.0.8) for consistency with the other override.
"brace-expansion@<1.1.16": "^5.0.0",
"brace-expansion@>=2.0.0 <2.1.2": "^2.1.2",
"brace-expansion@>=4.0.0 <5.0.8": "^5.0.8",
| "ajv@>=7.0.0-alpha.0 <8.18.0": "^8.18.0", | ||
| "axios@<1.18.0": "^1.18.0", | ||
| "basic-ftp@<=5.2.2": "^5.3.0", | ||
| "brace-expansion@<1.1.16": "^1.1.16", | ||
| "brace-expansion@<1.1.16": "^5.0.8", | ||
| "brace-expansion@>=2.0.0 <2.1.2": "^2.1.2", | ||
| "brace-expansion@>=4.0.0 <5.0.8": "^5.0.8", |
This PR contains the following updates:
^1.1.16→^5.0.8brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
CVE-2026-14257 / GHSA-mh99-v99m-4gvg
More information
Details
Summary
expand()bounds the number of results it produces (themaxoption,100_000by default) but not their length. By chaining many brace groups,an attacker keeps the result count under
maxwhile making every result growwith the number of groups. Building
maxlong results — plus the intermediatearrays combined at each brace group — exhausts memory and crashes the Node
process with an uncatchable out-of-memory error.
try/catcharoundexpand()does not help: the fatal error terminates the process.A ~7.5 KB input (
'{a,b}'.repeat(1500)) is enough to crash a default Nodeprocess.
Details
For
Nchained brace groups such as'{a,b}'.repeat(N):2^N, immediately capped atmax(100_000), so themaxprotection appears to hold, butNcharacters long, so the total output size ismax × Ncharacters, which grows without bound inN.expand_combines each brace set with the fully-expanded tail:The loop guard
expansions.length < maxlimits how many strings are built, butnothing limits how long they get. Each recursion level materializes another
array of up to
maxstrings, one character longer than the level below, and —because V8 represents
pre + N[j] + post[k]as a cons-string (rope) thatreferences
post[k]— those intermediate strings stay reachable through thewhole chain. Memory therefore scales with
max × N.Measured on
5.0.7('{a,b}'.repeat(N), defaultmax):Proof of concept
Impact
Any application that passes attacker-influenced strings to
brace-expansion.expand()— directly, or transitively viaminimatch/globbrace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.
Remediation
Upgrade to a patched release. The fix bounds the total number of characters a
single
expand()call may accumulate (EXPANSION_MAX_LENGTH, default4_000_000, configurable via a newmaxLengthoption), applied inside theoutput-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how
maxalready truncates —instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting
maxmeasure ~1M characters), so legitimateinput is unaffected.
After the fix,
'{a,b}'.repeat(1500)returns a bounded, truncated result in~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.
The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly
O(N × maxLength)work on this input class). A streamingrewrite that produces output in
O(total output size)can be a non-urgentfollow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to
expand()/ glob brace patterns, or pass a small explicitmaxandmaxLength.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion@<1.1.16)
v5.0.8Compare Source
v5.0.7Compare Source
v5.0.6Compare Source
v5.0.5Compare Source
v5.0.4Compare Source
v5.0.3Compare Source
v5.0.2Compare Source
v4.0.1Compare Source
5a5cc170b6a978v4.0.0Compare Source
278132bdd72a59tea.yaml70e4c1bAs a precaution to not risk breaking anything with
278132b, this is a new semver major releasev3.0.6Compare Source
v3.0.5Compare Source
v3.0.4Compare Source
v3.0.3Compare Source
v3.0.2Compare Source
v3.0.1Compare Source
3059c078229e6f15f9b3cv3.0.0Compare Source
c0360e868c0e379e781e93494c4ddd5a4cb6dad209teste3dd8aed23ede91eb3fa41e7c9cd252053761a94f1dc741cf8ee56265c8756a05978a7v2.1.4Compare Source
v2.1.3Compare Source
v2.1.2Compare Source
v2.1.1Compare Source
c3a817cv2.1.0Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
14f1d91ed7780a36603d5v2.0.1Compare Source
v2.0.0v1.1.17Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.