Vulnerability GHSA-vfj7-8cjw-p6xm

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
14 days ago
September 18, 2026 at 06:31 PM UTC
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
0.1.0 - 3.0.3
0.1.0 - 3.0.3

Summary

braces vulnerable to stack-exhaustion denial of service through deeply nested patterns

Details

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

Impacted packages

Timeline

Published
14 days ago
September 18, 2026 at 06:31 PM UTC
Last Modified
1 hour ago
October 02, 2026 at 10:45 PM UTC