CVE-2026-102278
Published 28 September 2026 · tracked since 29 September 2026
Description
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before ou
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102264 LOW 3.5
- CVE-2026-102263 MEDIUM 4.7
- CVE-2026-102414 LOW 3.7
- CVE-2026-102422 HIGH 8.1
- CVE-2026-102247 MEDIUM 6.8
- CVE-2026-96326 HIGH 7.2
- CVE-2026-101858 MEDIUM 4.7
- CVE-2026-101859 MEDIUM 5.4
- CVE-2026-101860 HIGH 8.8
- CVE-2026-101280 HIGH 7.3