CVE-2026-25547

Aliases:GHSA-7h2j-956f-4vf2DEBIAN-CVE-2026-25547CGA-22m9-3mhh-rjx8CGA-37gq-mrm7-4q2wCGA-49cg-jqmj-6m49CGA-5jw5-r8cg-38gxCGA-6cq5-2rxr-v2vqCGA-6rwj-m2h2-xj2pCGA-7rc7-g766-p365CGA-944f-j466-mf37CGA-fgcq-gfc8-jj5pCGA-g8rr-x696-x3w7CGA-gcq4-wm3h-55qwCGA-m66h-cfv4-8vc4CGA-pw4m-gvf2-4vjvCGA-2q5q-h56h-m5ggCGA-3x94-4677-25jhCGA-4p72-cf68-v4jcCGA-9rm6-8mgv-f59gCGA-h75g-7x3q-mrghCGA-h9jp-96h4-rmvmCGA-j3jh-96g2-xjc6CGA-jh2v-39rr-hhrjCGA-qm63-3h45-c9qmCGA-qqv2-6gv8-rcxgCGA-r4jc-4mrj-pm4mCGA-v5mg-x9cg-9q6hCGA-vcrg-mfj2-82jjCGA-w8vr-pvjj-pmqxCGA-wv3p-5cwv-vch8
Deferred
Published: 04 Feb 2026, 21:51
Last modified:05 Feb 2026, 14:31

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.2 CRITICAL
v4.0 (cve.org)
EPSS Score
0.5% LOW
1% probability +0.48%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Feb 2026, 21:51
Published
Vulnerability first disclosed
05 Feb 2026, 14:31
Last Modified
Vulnerability information updated

Description

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.

CVSS Metrics

  • v4.0CRITICALScore: 9.2CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
  • v4.0CRITICALScore: 9.2CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS Trends

Current EPSS score: 0.50% Percentile: 42%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • chainguardactions-runner

    < 2.331.0-r3

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-fips-2025.12

    all

  • chainguarddrupal-11.3

    < 11.3.13-r1

  • chainguardlerna

    < 9.0.3-r3

  • chainguardlibrechat

    < 0.8.2-r1

  • chainguardnode-gyp

    < 12.2.0-r2

  • chainguardnpm

    < 11.9.0-r0

  • chainguardpulumi-language-nodejs

    < 3.217.1-r2

  • chainguardrenovate

    < 43.3.1-r0 | < 43.2.4-r0

  • chainguardsqlpad

    < 7.5.7-r8

  • wolfilerna

    < 9.0.3-r3

  • wolfinode-gyp

    < 12.2.0-r2

  • wolfinpm

    < 11.9.0-r0

  • wolfipulumi-language-nodejs

    < 3.217.1-r2

  • wolfirenovate

    < 43.3.1-r0 | < 43.2.4-r0

  • wolfisqlpad

    < 7.5.7-r8

  • debiannode-brace-expansion

    all | all | all | < 2.0.3+~1.1.2-2

  • isaacsbrace-expansion

    < 5.0.1

  • @isaacsbrace-expansion

    < 5.0.1

References (5)