天下漏洞,尽知其名
HIGH

CVE-2026-102278 brace-expansion 栈溢出漏洞

影响攻击者可触发栈溢出导致 Node.js 进程崩溃,造成拒绝服务

AI 研判

brace-expansion 是广泛用于 Node.js 生态的字符串花括号展开库。该漏洞源于 expand_() 在处理深度嵌套的花括号分组时进行无控制的递归,导致原生调用栈耗尽。攻击者可通过提供恶意构造的嵌套模式使进程崩溃,形成拒绝服务。

影响范围

brace-expansion

brace-expansion 1.1.20、2.1.6、3.0.8、5.0.11 之前的版本均受影响。

漏洞详情

漏洞类型为不受控递归导致的栈耗尽(DoS)。当输入包含深度嵌套的花括号分组时,expand_() 在逗号成员和单集合展开处每层嵌套递归一次,在输出长度限制生效前就耗尽原生栈。由于该库常处理来自用户或配置的不可信模式,攻击者可构造深层嵌套字符串触发崩溃。

利用条件与风险

利用前提是应用将不可信输入作为花括号模式传入 brace-expansion。实战中可导致 Node.js 进程终止,属于远程可触发的拒绝服务风险。

修复建议

升级到 1.1.20、2.1.6、3.0.8 或 5.0.11 及更高版本。临时缓解措施包括限制输入嵌套深度或对不可信模式进行长度与结构校验。

原始情报

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.