SB2026051222 - Resource exhaustion in brace-expansion
Published: May 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-45149)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource consumption in the numeric range expansion logic when processing a string containing a single large numeric range. A remote attacker can supply a specially crafted expansion string to cause a denial of service.
User interaction is required to process the crafted expansion input.
Remediation
Install update from vendor's website.