chore(deps): update dependency brace-expansion@<2 to v2 [security] - #802
chore(deps): update dependency brace-expansion@<2 to v2 [security]#802renovate[bot] wants to merge 1 commit into
Conversation
|
2173ef8 to
e05e27b
Compare
|
View your CI Pipeline Execution ↗ for commit 85f3314
💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗ ☁️ Nx Cloud last updated this comment at |
@forgerock/davinci-client
@forgerock/device-client
@forgerock/journey-client
@forgerock/oidc-client
@forgerock/protect
@forgerock/sdk-types
@forgerock/sdk-utilities
@forgerock/iframe-manager
@forgerock/sdk-logger
@forgerock/sdk-oidc
@forgerock/sdk-request-middleware
@forgerock/storage
commit: |
|
Deployed eb38a33 to https://ForgeRock.github.io/ping-javascript-sdk/pr-802/eb38a33481f82c184ffc02977765ee00bbfae841 branch gh-pages in ForgeRock/ping-javascript-sdk |
📦 Bundle Size Analysis📦 Bundle Size Analysis🆕 New Packages🆕 @forgerock/device-client - 0.0 KB (new) ➖ No Changes➖ @forgerock/sdk-types - 9.1 KB 15 packages analyzed • Baseline from latest Legend🆕 New package ℹ️ How bundle sizes are calculated
🔄 Updated automatically on each push to this PR |
Codecov Report✅ All modified and coverable lines are covered by tests. ❌ Your project status has failed because the head coverage (24.11%) is below the target coverage (40.00%). You can increase the head coverage or adjust the target coverage. Additional details and impacted files@@ Coverage Diff @@
## main #802 +/- ##
==========================================
+ Coverage 18.07% 24.11% +6.03%
==========================================
Files 155 163 +8
Lines 24398 25797 +1399
Branches 1203 1686 +483
==========================================
+ Hits 4410 6221 +1811
+ Misses 19988 19576 -412 🚀 New features to boost your workflow:
|
e05e27b to
8aad040
Compare
8aad040 to
706aeea
Compare
706aeea to
bc3070f
Compare
1cdb4b7 to
eb151a0
Compare
eb151a0 to
87d9ded
Compare
87d9ded to
85f3314
Compare
85f3314 to
5cdbbd8
Compare
This PR contains the following updates:
~1.1.15→~2.1.2brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp
More information
Details
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In
expand_,postis computed unconditionally at the top of the function, before the early-return branches that don't use it:For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but
expand_has already recursed into post over the entire remaining tail, only to throw the result away.Each level therefore spawns two recursive expansions over essentially the same remaining work:
T(n) = 2·T(n−1) ⇒ O(2ⁿ).The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
Proof of concept
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:AmberReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion@<2)
v2.1.2Compare Source
v2.1.1Compare Source
c3a817cv2.1.0Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
14f1d91ed7780a36603d5v2.0.1Compare Source
v2.0.0Compare Source
v1.1.18Compare Source
v1.1.17Compare Source
v1.1.16Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.