Inefficient regular expression complexity in brace-expansion - CVE-2026-25547

 

Inefficient regular expression complexity in brace-expansion - CVE-2026-25547

Published: April 6, 2026


Vulnerability identifier: #VU124876
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25547
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. When a remote attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process.


Affected software

brace-expansion
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Multi-Linux Manager Beta Client Tools for SLE Micro
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Multi-Linux Manager Beta Client Tools for SLE
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cockpit-tukit
mgrctl-zsh-completion
mgrctl-lang
mgrctl
mgrctl-debuginfo
mgrctl-bash-completion
firewalld-prometheus-config
dracut-wireless
golang-github-QubitProducts-exporter_exporter
python3-defusedxml
prometheus-postgres_exporter-debuginfo
prometheus-postgres_exporter
golang-github-prometheus-promu-debuginfo
golang-github-prometheus-promu
prometheus-blackbox_exporter
golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager-debuginfo
golang-github-lusitaniae-apache_exporter-debuginfo
golang-github-lusitaniae-apache_exporter
dracut-saltboot
supportutils-plugin-salt
golang-github-prometheus-node_exporter-debuginfo
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter-debuginfo
golang-github-boynux-squid_exporter
golang-github-prometheus-prometheus
golang-github-prometheus-prometheus-debuginfo
release-notes-susemanager-proxy
release-notes-susemanager
spacecmd
supportutils-plugin-susemanager-client
python3-uyuni-common-libs
python3-mgr-push
mgr-push
python3-rhnlib
python3-spacewalk-client-tools
spacewalk-client-tools
Multi-Linux-ManagerTools-Beta-SLE-Micro-release
grafana
grafana-debuginfo
nodejs22 (Red Hat package)
nodejs24 (Red Hat package)
cockpit-podman
cockpit-machines
cockpit
cockpit-system
cockpit-ws-debuginfo
cockpit-ws
cockpit-bridge-debuginfo
cockpit-debugsource
cockpit-debuginfo
cockpit-bridge
venv-salt-minion
Jira Software Data Center
Jira Service Management Data Center

How to mitigate CVE-2026-25547

Install updates from vendor's website.

brace-expansion - update to 5.0.1
Jira Software Data Center - addressed in versions 10.3.19, 11.3.4
Jira Service Management Data Center - addressed in versions 10.3.19, 11.3.4
cockpit-tukit - update to 0.0.3~git14.ff11a9a-150300.1.9.1
mgrctl-zsh-completion - addressed in versions 0.1.38-150000.1.30.1, 5.2.5-159000.2.3.2
mgrctl-lang - addressed in versions 0.1.38-150000.1.30.1, 5.2.5-159000.2.3.2
mgrctl - addressed in versions 0.1.38-150000.1.30.1, 5.2.5-159000.2.3.2
mgrctl-debuginfo - addressed in versions 0.1.38-150000.1.30.1, 5.2.5-159000.2.3.2
mgrctl-bash-completion - addressed in versions 0.1.38-150000.1.30.1, 5.2.5-159000.2.3.2
firewalld-prometheus-config - addressed in versions 0.1-150000.3.67.1, 0.1-159000.4.3.2
dracut-wireless - update to 0.1.1595937550.0285244-159000.2.2.1
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-150000.1.21.1, 0.4.0-159000.2.2.1
python3-defusedxml - update to 0.7.1-159000.4.2.1
prometheus-postgres_exporter-debuginfo - update to 0.10.1-159000.2.2.1
prometheus-postgres_exporter - update to 0.10.1-159000.2.2.1
golang-github-prometheus-promu-debuginfo - update to 0.17.0-150000.3.30.1
golang-github-prometheus-promu - update to 0.17.0-150000.3.30.1
prometheus-blackbox_exporter - addressed in versions 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1
golang-github-prometheus-alertmanager - update to 0.28.1-159000.12.2.1
golang-github-prometheus-alertmanager-debuginfo - update to 0.28.1-159000.12.2.1
golang-github-lusitaniae-apache_exporter-debuginfo - addressed in versions 1.0.10-150000.1.26.1, 1.0.10-159000.2.2.1
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.10-150000.1.26.1, 1.0.10-159000.2.2.1
dracut-saltboot - addressed in versions 1.1.0-150000.1.65.1, 1.1.0-159000.2.2.1
supportutils-plugin-salt - update to 1.2.3-159000.4.2.1
golang-github-prometheus-node_exporter-debuginfo - update to 1.9.1-159000.4.2.1
golang-github-prometheus-node_exporter - update to 1.9.1-159000.4.2.1
golang-github-boynux-squid_exporter-debuginfo - addressed in versions 1.13.0-150000.1.12.1, 1.13.0-159000.2.2.1
golang-github-boynux-squid_exporter - addressed in versions 1.13.0-150000.1.12.1, 1.13.0-159000.2.2.1
golang-github-prometheus-prometheus - addressed in versions 3.5.0-150000.3.67.1, 3.5.0-159000.4.3.2
golang-github-prometheus-prometheus-debuginfo - update to 3.5.0-159000.4.3.2
release-notes-susemanager-proxy - update to 4.3.17-150400.3.107.1
release-notes-susemanager - update to 4.3.17-150400.3.151.1
spacecmd - addressed in versions 5.0.15-150000.3.142.1, 5.2.6-159000.4.3.1
supportutils-plugin-susemanager-client - update to 5.2.2-159000.4.2.1
python3-uyuni-common-libs - update to 5.2.3-159000.2.3.1
python3-mgr-push - update to 5.2.3-159000.2.3.1
mgr-push - update to 5.2.3-159000.2.3.1
python3-rhnlib - update to 5.2.4-159000.4.3.1
python3-spacewalk-client-tools - update to 5.2.4-159000.4.3.1
spacewalk-client-tools - update to 5.2.4-159000.4.3.1
Multi-Linux-ManagerTools-Beta-SLE-Micro-release - update to 5-159000.3.3.1
grafana - addressed in versions 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2
grafana-debuginfo - addressed in versions 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2
nodejs22 (Red Hat package) - update to 22.22.2-1.el10_1
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
cockpit-podman - update to 33-150300.6.9.1
cockpit-machines - update to 249.1-150300.5.6.1
cockpit - update to 251.3-150300.6.9.1
cockpit-system - update to 251.3-150300.6.9.1
cockpit-ws-debuginfo - update to 251.3-150300.6.9.1
cockpit-ws - update to 251.3-150300.6.9.1
cockpit-bridge-debuginfo - update to 251.3-150300.6.9.1
cockpit-debugsource - update to 251.3-150300.6.9.1
cockpit-debuginfo - update to 251.3-150300.6.9.1
cockpit-bridge - update to 251.3-150300.6.9.1
venv-salt-minion - update to 3006.0-159000.5.3.2

External References

Related Security Bulletins