天下漏洞,尽知其名
HIGH

CVE-2026-102276 brace-expansion 栈溢出漏洞

影响可导致 Node.js 进程崩溃,造成拒绝服务

AI 研判

brace-expansion 是广泛用于 Node.js 生态的字符串展开库,被 minimatch、glob 等大量依赖间接引用。该漏洞中,攻击者构造的恶意花括号模式会在 parseCommaParts 中触发递归与参数数组的原生栈耗尽,在 max/maxLength 限制生效前即导致进程终止。

影响范围

brace-expansion

brace-expansion 1.1.19、2.1.5、3.0.7、5.0.10 之前的版本受影响,修复版本为 1.1.19、2.1.5、3.0.7、5.0.10。

漏洞详情

漏洞属于栈耗尽型拒绝服务。parseCommaParts 对每个花括号分组递归处理剩余内容,同时用 push.apply 将超大逗号分段数组的每个元素作为函数参数传入,从而分别触发深递归和参数数组两条原生栈耗尽路径。由于栈耗尽发生在 max 或 maxLength 输出限制之前,进程会直接崩溃。

利用条件与风险

利用前提是应用将不可信输入传入 brace-expansion 展开(如 glob 匹配、路径处理等场景),无需认证即可触发,实战中可造成服务不可用。

修复建议

升级到 1.1.19、2.1.5、3.0.7 或 5.0.10 及以上版本;临时缓解可对传入的展开模式长度和花括号分组数量做限制,或避免将不可信输入直接用于花括号展开。

原始情报

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.