CVE-2026-14257

Aliases:UBUNTU-CVE-2026-14257DEBIAN-CVE-2026-14257GHSA-mh99-v99m-4gvgCGA-2323-2x7m-479jCGA-24qq-q5f4-42rmCGA-26qj-jp55-cvwcCGA-2783-jx82-rmqvCGA-28v7-66q7-24vqCGA-29cq-gw56-97v6CGA-2fj5-qpw5-pmf4CGA-2frp-rc97-g3q3CGA-2m2v-3v29-357pCGA-2qgp-f2xf-5j7qCGA-2wrw-5v42-67rxCGA-3294-qqp5-f4w5CGA-3372-4cpm-58x6CGA-33p4-qhr9-rm65CGA-39j3-4mfw-mg4gCGA-3fv2-fqhg-9x5fCGA-3h8g-mr2q-xxqcCGA-3m3r-mj34-4rc6CGA-3rgq-pq4c-chwpCGA-3v6h-2mw5-x43qCGA-3w5x-r8mr-x2xhCGA-42qc-vrc2-r28cCGA-4crr-pv39-r8qmCGA-4jj8-qxg3-6m4rCGA-4jm2-9wqx-7mwqCGA-4p5f-r83p-34c7CGA-4q8v-j7vp-pm2gCGA-52jq-gcw2-3rv7CGA-52r4-j3hr-3qm2CGA-53hx-h9rp-7574CGA-5q86-63px-999gCGA-625h-rxrw-jxx9CGA-679r-p9p6-9qcfCGA-6872-qrrf-mvm4CGA-6hf9-6j4p-2q3vCGA-6hg5-vmvg-fqm6CGA-72jr-7r8v-4m7hCGA-7fp3-mg9g-f6p7CGA-84qh-hv82-qp9xCGA-878c-7rp7-rhp6CGA-8jr6-c3gv-wqqhCGA-8xwc-9m37-67c4CGA-9383-6xqw-q874CGA-94gx-gxfh-fm6wCGA-9fmf-fhj3-8qf3CGA-9m3p-cq5x-g7hhCGA-9rgm-rrc4-gj4jCGA-9x7v-5g9r-4h2xCGA-c3fm-xwj6-v53vCGA-c57q-fh38-v7ccCGA-c6hr-8w9q-xgg8CGA-c9mc-87g3-3mwvCGA-ccw3-7vmp-c4p3CGA-cpg7-7qvh-2h8gCGA-cq26-x3g3-29w8CGA-f35v-rm5m-mw6pCGA-f37r-77rj-q3q2CGA-f8j8-qrfw-v7fwCGA-f958-h9ww-q2qxCGA-fvpf-72w8-qj74CGA-g4x8-9m46-364hCGA-ggmc-v66r-7849CGA-gh86-gvhf-j8x2CGA-gmxq-rf26-v7frCGA-gxc7-7p9p-4qwmCGA-h34h-qm7q-v5wmCGA-h5xj-qx7v-2vwgCGA-h6qf-3xmm-2g8wCGA-h8h7-2h8x-g2qrCGA-h9g4-g6vq-5g8mCGA-h9r5-c45f-jg5gCGA-hc5m-j88w-cjwjCGA-hcv6-p64f-hr35CGA-hfw3-jgfc-9ghxCGA-hhh5-jwwq-h9cfCGA-hhv9-whph-r55vCGA-hp7f-7c4q-m72jCGA-hv7j-h828-3gc5CGA-j3w5-x8vp-rh26CGA-j7h4-vvr6-w64hCGA-jch3-x9h7-9prwCGA-jg9c-crw4-cg2cCGA-jqc2-mj35-mfm2CGA-mjxx-3ffw-xm5xCGA-mp25-9phc-7gcrCGA-mwqw-7q2r-9q5wCGA-p7jh-fg3p-3x7fCGA-p8gx-7m6f-h6hgCGA-p98w-6vpr-ch8gCGA-pc25-4p2r-g897CGA-pfpv-pjmj-gjcgCGA-ph22-3m6v-hghwCGA-pmvh-9hhp-q4h9CGA-pq6w-p3jf-p4vwCGA-pvj5-wr5h-7m8vCGA-228p-57v4-whqvCGA-2379-qpg7-qqgxCGA-237j-xr85-8384CGA-244x-v49r-8wrpCGA-24m5-p5g7-hhwvCGA-24mx-qjgg-6mc8CGA-24v5-79q8-r58xCGA-25g2-3fw6-8wj3CGA-25w7-wf3v-6vgcCGA-27cp-pv5f-jmq9CGA-27wh-v57c-3mwwCGA-28pf-f376-c64vCGA-2c9w-x4p3-2vwmCGA-2fvv-3hf6-26fxCGA-2gj2-35f6-7xc5CGA-2j5w-p54p-qqc7CGA-2jgj-v2fx-9w88CGA-2jm6-6cfm-mjw9CGA-2jrg-3hch-vjjwCGA-2jxh-wx6x-3pmjCGA-2m2x-gj49-x82vCGA-2pmc-cgv2-4m2mCGA-2qmf-g2w3-hc5gCGA-2qvx-9qf3-gv93CGA-2qw2-r3q6-2r54CGA-2w6q-p522-ghcpCGA-2wqj-qfhf-vr7pCGA-32pw-f84v-m2vpCGA-3363-9425-q29qCGA-33p2-jjg6-jq8fCGA-33pg-vvgm-6jp7CGA-343q-g23w-mq7gCGA-39w4-3hp2-rg62CGA-3hcw-v9gf-6w4mCGA-3hw9-vfwp-qpxrCGA-3jh8-rj34-6xc8CGA-3qx5-9v5g-28h4CGA-3vj5-jmfm-pffvCGA-3vmv-chj6-74jfCGA-3x82-prj8-598wCGA-4334-8hvf-7xv6CGA-448m-x525-4wcgCGA-47gx-33r9-mp2hCGA-47wh-7gwc-qmf2CGA-4983-9cr9-gcxrCGA-49pg-qfgm-v2mqCGA-4c9p-95gr-fqc4CGA-4cqm-pvpx-qvf6CGA-4j5f-rx5m-r4jpCGA-4mjh-6m7c-vvw9CGA-4mm7-hc2w-38rgCGA-4pwp-57hx-6gm8CGA-4qxp-32hh-x389CGA-4r54-5cxj-2hjvCGA-4r7h-3295-p7g4CGA-4vr6-hqhr-75w5CGA-4w27-4gqv-7hm7CGA-52c8-qr98-f6f7CGA-52x4-jhgm-9w8xCGA-53hr-p6jh-jjf2CGA-53q7-8mqh-c46mCGA-55q4-3ghp-2m7fCGA-55qq-225w-qh48CGA-56gr-5j2p-96v2CGA-57mf-f89f-cq2hCGA-582c-mx2q-j333CGA-586j-xmmp-74p9CGA-5c27-rfqf-v4qrCGA-5c79-wjj5-2q5gCGA-5cp8-j29m-jq4pCGA-5px8-67mf-6mfqCGA-5rw5-c2m3-6qc9CGA-627p-fp24-fwmrCGA-629h-x3r6-h94wCGA-64gc-589r-r226CGA-656p-wcvp-2p9vCGA-66pp-49wq-rc5hCGA-69hc-7px2-r8fjCGA-6fm5-p64v-p5v3CGA-6ghx-r9ff-m5c7CGA-6gv3-23qp-hxgfCGA-6j95-7xgw-f2j4CGA-6m5p-w84g-wjp5CGA-6m99-228q-r9wxCGA-6mgg-p7gw-px82CGA-6p3c-4v8p-99r6CGA-6pmf-vmj3-9mmcCGA-6qfw-rhgp-5f59CGA-6qvc-v2g6-w6jxCGA-6v8q-v5g5-ch57CGA-6vc3-rmjp-hvfmCGA-6x9c-cxr4-8v45CGA-75p3-77r8-rr5xCGA-75vm-7495-h3jcCGA-779p-2xp3-47h3CGA-782f-rgff-vmxmCGA-79x2-hgwg-pv45CGA-7fgh-qxwh-f3chCGA-7g3g-2r9q-9v54CGA-7jf6-3pc4-9xfwCGA-7jjv-hv3x-p69wCGA-7m6m-57cj-4h92CGA-7pq7-85p6-28vjCGA-7qcx-2hhx-vq3jCGA-7qf6-j3m4-xc28CGA-7qh9-5xwr-86g4CGA-7rg7-4xm8-rmpcCGA-7vv3-35gw-8rm5CGA-852f-3ph6-rhh9CGA-85rc-r6wj-rvr5CGA-8jcg-g8rq-w4j9CGA-8jq6-296q-w5v3CGA-8vmj-9qpr-wcfxCGA-8wmv-2429-3qgcCGA-8wxq-2x73-xwjmCGA-8x44-v2gc-4qg9CGA-8x85-4xpj-44qrCGA-8xm6-5mh8-p4cpCGA-93cv-q8vh-x2xgCGA-9435-94qv-5gr8CGA-94hq-vw78-hx87CGA-94mv-5vv4-296wCGA-95p4-vq69-m52cCGA-974c-v78j-gr39CGA-9779-xwmc-2q86CGA-9872-398f-gv3jCGA-9892-rf64-7758CGA-99w5-wgvg-wm3qCGA-9h8m-7q57-83qqCGA-9hm5-wcvx-26g9CGA-9m9h-42v9-86cqCGA-9p55-3fmr-qcg7CGA-9qxq-9vrg-mq5qCGA-9r8x-hrq7-x62wCGA-9v26-p6pw-86wpCGA-9wgg-6gq6-rpmvCGA-9wpm-cfr2-98p4CGA-c23r-pjwg-834cCGA-c25c-4rf9-xmwqCGA-c464-89rf-96rxCGA-c496-p84p-vqr3CGA-c762-mf88-hg6vCGA-c7hg-64gw-8g33CGA-c983-293q-9rv9CGA-c9pp-hh3h-6wm7CGA-cgpw-vfxv-8cpxCGA-cgxr-qqv5-4cr3CGA-cmp8-8cpj-w93jCGA-cqpj-hg9w-fwxfCGA-crpx-628h-9r46CGA-f37j-vvr5-3mx9CGA-f4p4-rwgf-6wp9CGA-f4rh-hm6j-m57wCGA-f5wc-v638-gx6cCGA-f863-f2h2-3f27CGA-f878-87p2-qjvmCGA-f9gh-x7xp-pwrcCGA-fg8g-4q47-fqqhCGA-fgpm-7wp3-v97gCGA-fhc6-jf84-42v7CGA-fhrr-x8fp-rm3cCGA-fm33-36m8-c4w4CGA-fm45-v9c2-82h5CGA-fm46-ccpm-f3xpCGA-fmxc-cw56-hgv2CGA-fp7f-hrrh-xq9fCGA-fpgf-rvv6-jw5rCGA-fq3r-2jv9-rjcfCGA-fqg6-mm4g-j668CGA-fv45-7hqv-j6hvCGA-fv8r-g2m3-695qCGA-fxfj-h4j3-9cfhCGA-g2rx-r537-vmp2CGA-g32m-8r6m-8xfwCGA-g33j-ph7c-xxpjCGA-g34x-8886-w85xCGA-g4j6-37pv-gr9gCGA-g68q-jq2c-7v39CGA-g6f7-4pgw-6f6xCGA-g7vf-23mp-552mCGA-g84h-r5cj-9w5jCGA-g99v-h43q-p5xxCGA-g9qm-92gv-5w9wCGA-g9qp-3h7f-wq2pCGA-gfqg-cg9x-3jffCGA-ggx5-v7qm-p845CGA-gj7v-6rm3-5mv6CGA-gjqw-v22r-w798CGA-gq88-jvg3-59grCGA-gqp7-9w5v-r4h6CGA-gxhw-77g2-2593CGA-gxw4-84m9-xvvjCGA-h2m9-vxg5-2rg8CGA-h355-fhr8-wxg2CGA-h4c2-4xw9-87p4CGA-h537-8fm8-hx33CGA-h86h-m4jj-7c7wCGA-h9p7-rhxf-4j9rCGA-hf45-ccqq-7w4gCGA-hf99-g6qm-h4fvCGA-hjgr-frcv-5xf7CGA-hjh6-9xhr-7q8cCGA-hjhj-mcv8-2jx7CGA-hpgw-mqwm-44w8CGA-hq53-phv5-69c7CGA-hqgc-j543-hvgvCGA-hvq2-c6mq-6c7cCGA-hx98-3655-79q6CGA-hxqx-5r9g-4cr8CGA-hxxh-rjqx-rhjrCGA-j2gq-jmvj-vf7rCGA-j2jq-wh52-2777CGA-j2m3-hwcr-p3mrCGA-j3cv-6956-f23pCGA-j4g4-rr5x-63jfCGA-j5ww-j72x-xcw8CGA-j72m-j73x-p7whCGA-j7qg-6p5j-wm65CGA-j9f3-mw7q-5x9cCGA-j9mc-vg34-h4m8CGA-jfjj-w4f7-wvpjCGA-jh2q-q26c-fpwjCGA-jrj3-627x-mx2cCGA-jx9h-hwjj-gp24CGA-jxj4-v4cx-g7rgCGA-m2p5-67vr-mch7CGA-m43f-3fvr-56q7CGA-m462-728r-m26hCGA-m5pf-q535-8fp3CGA-m5x6-c995-w5gmCGA-m73c-prj3-3pphCGA-m8h4-777p-xg22CGA-m9vj-h76j-7hhcCGA-mf4x-8cv3-76pqCGA-mgj6-h74w-8q55CGA-mh5f-rw95-6p95CGA-mjfr-2cqh-2q4wCGA-mmxr-78hg-f5xwCGA-mpwc-qw4m-jwh4CGA-mq3c-5jjw-45hqCGA-mr9r-mmxr-c8p5CGA-mv22-5x6g-c9g3CGA-mx2c-2cp7-mhwqCGA-mxp6-xqqg-2697CGA-p2r3-c3vw-9vw7CGA-p342-6wx6-9hm7CGA-p38v-4q3c-23xqCGA-p53j-mx9v-q683CGA-p6pr-4wx5-4jhwCGA-p8ch-wcph-m2vgCGA-p8fw-68r9-xjqvCGA-p99w-qw3p-p63hCGA-pgc3-cp4p-6m48CGA-ph6m-8g4w-xr2hCGA-pj52-255j-h7pjCGA-pjm7-q24x-795hCGA-pmm5-xvxq-jjm4CGA-pr4q-qrv8-hgh7CGA-pv9j-qm97-998mCGA-pvm7-74r3-r7h9CGA-pwq4-xx9h-32cmCGA-q6fm-v344-f66xCGA-q6qh-32qm-7q63CGA-q845-6gmr-6577CGA-q87j-f3qw-97rgCGA-q89v-v4w5-6r35CGA-q964-hhqp-4mc2CGA-qfrr-f8hw-7m53CGA-qgc6-6vj2-m572CGA-qhfx-3x2g-6jw5CGA-qpgj-m5q7-249wCGA-qq58-35mv-vc5jCGA-qqjv-g5jc-6q9vCGA-qqwv-vqxm-vjw3CGA-qrq9-v4v7-pxhjCGA-qvgc-gjj6-pfmpCGA-qvw3-x2jh-4qqhCGA-qw2h-97x4-mwhpCGA-qw99-qqvw-r529CGA-qwg3-p36m-96mrCGA-qxhg-9frx-4q5jCGA-qxww-2p4x-mpp3CGA-r247-q7fr-g9mqCGA-r2hf-ppr5-x7p8CGA-r472-q78g-922mCGA-r53p-82c5-56wxCGA-r5mw-xvq9-w8rqCGA-r652-7h4q-4gp2CGA-r6ww-hfcm-64m9CGA-r6wx-cr8f-58hgCGA-r7xq-4c4x-mx4wCGA-rc7f-xjm9-34q9CGA-rcpg-76x2-gv4fCGA-rcv8-cw5r-c6p5CGA-rf7q-x9m9-h37cCGA-rhxm-wmcp-5cvqCGA-rj6h-75mq-mr94CGA-rjcw-6h3h-wg2vCGA-rjf3-rfv2-8gg6CGA-rjq3-fv6r-jc4hCGA-rm32-7gv6-hqjvCGA-rmm7-vj25-jfhjCGA-rp6j-pwxf-9j8mCGA-rrqx-92gx-3rppCGA-rw62-hmx5-xgwhCGA-rw6j-46c2-39xgCGA-rx5x-45g7-mwf3CGA-v42j-p8mv-5cwpCGA-v4r9-mhvg-w28cCGA-v5c9-6gp5-4j78CGA-v5q9-6m8f-xmf3CGA-v6vj-p3w5-7hjpCGA-v886-797h-m3qgCGA-v8gm-qjf2-98h2CGA-v9rq-2mxx-94v8CGA-vggr-jmmj-r3pfCGA-vgjf-qmf8-4mr8CGA-vgxj-qrm8-2jjhCGA-vh94-8r97-p59qCGA-vhr7-p466-v9mfCGA-vmc9-4hrp-mqxxCGA-vmgm-c83w-v8x8CGA-vmrx-r28q-74q9CGA-vqvw-pv53-38mjCGA-vr5x-jpqj-322hCGA-vr8q-w8m6-hwp3CGA-vrqm-wv42-2gh2CGA-vvgg-fmgm-4chxCGA-vvw6-65cm-w7p2CGA-vw35-4fwv-qc7xCGA-vwm6-vmc6-88rxCGA-vxmf-97hc-48v6CGA-w3jh-938x-9qx7CGA-w4vh-5hfw-wmq6CGA-w57c-q375-vcrqCGA-w5v9-fwf6-w4jhCGA-w7vc-jf2j-mwh4CGA-w88c-qw53-fw27CGA-w8v2-vqw2-w8jhCGA-w8v4-7jm2-j952CGA-w8v6-mvww-6g9cCGA-w947-8cjr-9jh5CGA-w9v3-2crq-48hcCGA-wc2m-g8r2-c6vrCGA-wc8p-mmrx-3gh4CGA-wcm3-hw45-285jCGA-whg3-r3f3-rqr6CGA-whj3-8mhv-9w68CGA-wjj7-wfgh-mw8rCGA-wpfx-q7w4-4f73CGA-wqqp-75qc-g64wCGA-ww7x-9j3x-p97xCGA-wwwv-2426-hgf6CGA-x236-grx3-fchrCGA-x2vj-rjq3-rcqpCGA-x4wx-qvpj-p6wcCGA-x6hv-3jq4-4q64CGA-x769-73m4-f5g4CGA-x86f-g9vc-j9f7CGA-x967-x6mr-p5jrCGA-xm3v-wmqh-jxw2CGA-xmg4-hmfm-v4fqCGA-xpqv-4mhm-hjvjCGA-xpvp-cx55-3x6pCGA-xpw7-9645-qx49CGA-xwhv-frmg-7h38CGA-4xmf-95h4-qxw8CGA-qmx7-qx7w-x5wjCGA-gq44-rqqx-w2fqCGA-mp22-cfg3-7f5mCGA-3ggj-5x83-x4q9CGA-c98j-x882-x7g6CGA-g53r-9gf3-8qm4CGA-vjf4-2pcv-7948CGA-7hvx-w9qh-mjj5CGA-m7fr-8h9p-9chcCGA-q859-gv52-rwff
Advisory lineage Upstream: 0 Downstream: 15
Analyzed
Published: 23 Jul 2026, 12:54
Last modified:23 Jul 2026, 14:44

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.64% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jul 2026, 12:54
Published
Vulnerability first disclosed
23 Jul 2026, 14:44
Last Modified
Vulnerability information updated

Description

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.64% Percentile: 49%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardactions-runner

    < 2.336.0-r2

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.4-r15 | < 3.11.14.4-r16

  • chainguardarangodb-3.12

    < 3.12.9.4-r15

  • chainguardargo-workflows-ui-3.6

    all

  • chainguardargo-workflows-ui-3.7

    < 3.7.17-r1

  • chainguardargo-workflows-ui-4.0

    < 4.0.8-r2 | < 4.0.11-r0

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.2

    < 2026.2.6-r7

  • chainguardauthentik-2026.5

    < 2026.5.6-r4 | < 2026.5.6-r3

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r3

  • chainguardazurite

    < 3.35.0-r2

  • chainguardbash-language-server

    < 5.6.0-r4

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardfoxx-cli

    < 2.1.1-r10

  • chainguardgemini-cli

    < 0.49.0-r6

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.8-r1

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardgraalvm-25-ce-nodejs

    < 25.0.4-r2

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r40

  • chainguardkibana-8.17

    < 8.17.10-r32

  • chainguardkibana-8.17-bitnami

    < 8.17.10-r32

Showing first 50 affected entries in server-rendered view.

References (15)