THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rgw5-rvv9-x895 (high) — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

[GHSA] GHSA-rgw5-rvv9-x895 (high) — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

highgithub_advisoriesPublished 2026-08-03

GHSA-rgw5-rvv9-x895 Severity: high CVE: CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

### Summary

The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rgw5-rvv9-x895