npm vulnerability intelligence

brace-expansion NPM Package
Vulnerability Check

Brace expansion as known from sh/bash

High severity MIT v5.0.9
Vulnerability Analysis OSV Live

brace-expansion

v5.0.9 · MIT · 606,656,605 dl/wk

Advisory Breakdown

Critical 0
High 4
Moderate 2
Low 1

Severity Rating

High severity

7 advisories

High severity

Weekly downloads

606,656,605

Total advisories

7

Latest version

5.0.9

License

MIT

Known advisories

OSV records for the npm ecosystem

7
GHSA-3jxr-9vmj-r5cp CVE-2026-13149 high

brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Affected: >=3.0.0 <5.0.7, >=0 <1.1.16, >=2.0.0 <2.1.2 Fixed in: 5.0.7, 1.1.16, 2.1.2 Updated Jul 21, 2026
View source
GHSA-832h-xg76-4gv6 CVE-2017-18077 high

ReDoS in brace-expansion

Affected: >=0 <1.1.7 Fixed in: 1.1.7 Updated Nov 8, 2023
View source
GHSA-f886-m6hf-6m8v CVE-2026-33750 moderate

brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Affected: >=4.0.0 <5.0.5, >=3.0.0 <3.0.2, >=2.0.0 <2.0.3, >=0 <1.1.13 Fixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13 Updated Mar 27, 2026
View source
GHSA-jxxr-4gwj-5jf2 CVE-2026-45149 moderate

brace-expansion: Large numeric range defeats documented `max` DoS protection

Affected: >=5.0.0 <5.0.6 Fixed in: 5.0.6 Updated Jun 9, 2026
View source
GHSA-mh99-v99m-4gvg CVE-2026-14257 high

brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash

Affected: >=4.0.0 <5.0.8, >=3.0.0 <3.0.3, >=2.0.0 <2.1.3, >=0 <1.1.17 Fixed in: 5.0.8, 3.0.3, 2.1.3, 1.1.17 Updated Jul 31, 2026
View source
GHSA-rgw5-rvv9-x895 CVE-2026-69152 high

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

Affected: >=0 <1.1.18, >=2.0.0 <2.1.4, >=3.0.0 <3.0.6, >=4.0.0 <5.0.9 Fixed in: 1.1.18, 2.1.4, 3.0.6, 5.0.9 Updated Aug 4, 2026
View source
GHSA-v6h2-p8h4-qcjw CVE-2025-5889 low

brace-expansion Regular Expression Denial of Service vulnerability

Affected: >=2.0.0 <2.0.2, >=1.0.0 <1.1.12, >=3.0.0 <3.0.1, >=4.0.0 <4.0.1 Fixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1 Updated Feb 4, 2026
View source

Checked Aug 12, 2026, 2:37 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
brace-expansion
Ecosystem
npm
Latest version
5.0.9
License
MIT
Weekly downloads
606,656,605

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 2:37:12 PM