Inefficient regular expression complexity in brace-expansion - CVE-2025-5889

 

Inefficient regular expression complexity in brace-expansion - CVE-2025-5889

Published: July 15, 2025


Vulnerability identifier: #VU112890
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5889
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote user can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

brace-expansion
QRadar Investigation Assistant
Storage Sentinel Anomaly Scan Engine
DB2 Data Management Console
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Data Product Hub
Knowledge Catalog Premium Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
WatsonX BI Assistant
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
IBM Business Automation Manager Open Editions
Maximo Application Suite - Visual Inspection Component
IBM Event Endpoint Management
Verify Identity Access Digital Credentials
Db2 Big SQL
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Voice Gateway
Communications Unified Assurance
watsonx.data
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
Oracle Communications Network Analytics Data Director
Event Streams
IBM QRadar Data Synchronization App
IBM App Connect Enterprise
IBM Security SOAR
IBM Security QRadar Analyst Workflow
Splunk Security Orchestration, Automation and Response (SOAR)
local-npm-registry
nodejs-brace-expansion
python311-pluggy
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python311-coverage-debuginfo
python-coverage-debugsource
python311-coverage
python311-pytest

How to mitigate CVE-2025-5889

Install updates from vendor's website.

brace-expansion - addressed in versions 1.1.12, 2.0.2, 3.0.1, 4.0.1
QRadar Investigation Assistant - update to 1.1.0
Voice Gateway - addressed in versions 1.0.8.16, 1.0.8.28
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
watsonx.data - update to 2.3.1
DB2 Data Management Console - update to 3.1.13.2
Guardium Data Security Center (GDSC) - update to 3.8.8
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.17.5
Data Product Hub - update to 5.2.1
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
WatsonX BI Assistant - update to 5.3
Maximo Application Suite - Monitor Component - addressed in versions 8.10.26, 8.11.24, 9.0.16, 9.1.6
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.24, 9.0.16, 9.1.6
IBM Business Automation Manager Open Editions - update to 9.3.0
Maximo Application Suite - Visual Inspection Component - update to 9.1.1
Event Streams - update to 12.2.2
IBM Event Endpoint Management - update to 11.7.0
IBM App Connect Enterprise - addressed in versions 12.0.12.16, 13.0.4.0
IBM Security SOAR - update to 51.0.7.1
local-npm-registry - update to 1.1.0-150400.9.3.1
nodejs-brace-expansion - update to 1.1.11-2
python311-pluggy - update to 1.5.0-150400.14.10.1
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
IBM Security QRadar Analyst Workflow - update to 3.0.1
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
IBM QRadar Data Synchronization App - update to 3.3.0
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
python311-pytest-cov - update to 6.2.1-150400.12.6.1
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
Db2 Big SQL - update to 8.2
python311-pytest - update to 8.3.5-150400.3.9.1

External References

Related Security Bulletins