Input validation error in brace-expansion - CVE-2026-33750

 

Input validation error in brace-expansion - CVE-2026-33750

Published: April 28, 2026


Vulnerability identifier: #VU128397
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33750
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in sequence generation in expand() when parsing a brace pattern with a zero step value. A remote attacker can supply a specially crafted pattern to cause a denial of service.

User interaction is required to process the crafted input.


Affected software

brace-expansion
Maximo Scheduler Optimizer
InfoSphere Optim Archive Viewer
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
openEuler
nodejs-brace-expansion

How to mitigate CVE-2026-33750

Install security update from vendor's website.

brace-expansion - addressed in versions 1.1.13, 2.0.3, 3.0.2, 5.0.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Jira Service Management Data Center - addressed in versions 10.3.20, 11.3.5
Confluence Data Center - addressed in versions 9.2.20, 10.2.10
Bitbucket Data Center - addressed in versions 9.4.19, 10.2.2
Jira Software Data Center - addressed in versions 10.3.20, 11.3.5
nodejs-brace-expansion - update to 1.1.11-3
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
InfoSphere Optim Archive Viewer - update to 11.7.0.14

External References

Related Security Bulletins