Source: node-braces Version: 3.0.3+~3.0.5-1 Severity: important Tags: security upstream Forwarded: https://github.com/micromatch/braces/issues/70 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-braces. CVE-2026-93687[0]: | braces through 3.0.3 contains a stack overflow vulnerability in the | recursive AST walkers that lack depth guards. Attackers can supply | deeply nested brace patterns under the character limit to exhaust | the call stack and terminate the Node.js process with an uncaught | RangeError. TTBOMK no fix upstream at time of writing this bugreport. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93687 https://www.cve.org/CVERecord?id=CVE-2026-93687 [1] https://github.com/micromatch/braces/issues/70 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

