Vulnerability GHSA-vfj7-8cjw-p6xm
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
14 days ago
September 18, 2026 at 06:31 PM UTC
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
0.1.0 - 3.0.3
0.1.0 - 3.0.3
Summary
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
Details
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 years ago
Uncontrolled resource consumption in braces
0.1.0 - 3.0.2 GHSA-grv7-fg5c-xmjg
0.1.0 - 3.0.2 GHSA-grv7-fg5c-xmjg
Low Risk
4 years ago
Regular Expression Denial of Service (ReDoS) in braces
2.2.0 - 2.3.0 GHSA-cwfw-4gq5-mrqx
2.2.0 - 2.3.0 GHSA-cwfw-4gq5-mrqx
Impacted packages
Timeline
Published
14 days ago
September 18, 2026 at 06:31 PM UTC
Last Modified
1 hour ago
October 02, 2026 at 10:45 PM UTC