Your message dated Sat, 03 Oct 2026 06:48:58 +0000
with message-id <[email protected]>
and subject line Bug#1149649: fixed in node-brace-expansion 2.1.7+~1.1.2-1
has caused the Debian Bug report #1149649,
regarding node-brace-expansion: CVE-2026-102276 CVE-2026-102277 CVE-2026-102278
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1149649: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149649
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-brace-expansion
Version: 2.1.4+~1.1.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for node-brace-expansion.
CVE-2026-102276[0]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10,
| crafted brace patterns can exhaust the native stack in
| parseCommaParts because parseCommaParts recursively processes the
| remainder once per brace group and uses push.apply to pass every
| element of a very large comma-part array as a function argument.
| Patterns containing many comma-separated brace groups trigger the
| recursive path, while the large array triggers the argument-array
| path without deep recursion. These paths cause recursive and
| argument-array native stack exhaustion before max or maxLength can
| limit output, potentially terminating the Node.js process in a
| process-terminating denial of service. This issue is fixed in
| versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10.
CVE-2026-102277[1]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12,
| the expand function handles untrusted {a},b}-shaped patterns with
| many trailing closing braces by restarting its scan once for each
| trailing closing brace. The successive full-input rescans with
| linear working-string growth cause quadratic CPU time and memory
| pressure that can block the Node.js event loop. The process
| eventually recovers, making the impact a recoverable CPU denial of
| service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and
| 5.0.12.
CVE-2026-102278[2]:
| The brace-expansion library generates arbitrary strings containing a
| common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11,
| deeply nested brace groups cause expand_() to recurse once per
| nesting level at comma-member and single-set expansion sites,
| exhausting the native stack before output limits can apply and
| potentially terminating the Node.js process. expand_ performs
| uncontrolled recursion for nested brace alternatives and single-part
| sets. deeply nested brace groups supplied as an untrusted pattern.
| expand_ is affected. expand is affected. Comma members is affected.
| Single set is affected. native stack exhaustion during nested sub-
| expansion. process-terminating denial of service. This issue is
| fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-102276
https://www.cve.org/CVERecord?id=CVE-2026-102276
[1] https://security-tracker.debian.org/tracker/CVE-2026-102277
https://www.cve.org/CVERecord?id=CVE-2026-102277
[2] https://security-tracker.debian.org/tracker/CVE-2026-102278
https://www.cve.org/CVERecord?id=CVE-2026-102278
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-brace-expansion
Source-Version: 2.1.7+~1.1.2-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-brace-expansion, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-brace-expansion
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 03 Oct 2026 08:20:17 +0200
Source: node-brace-expansion
Architecture: source
Version: 2.1.7+~1.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1149649
Changes:
node-brace-expansion (2.1.7+~1.1.2-1) unstable; urgency=medium
.
* Team upload
* New upstream version
(Closes: #1149649, CVE-2026-102276, CVE-2026-102277, CVE-2026-102278)
Checksums-Sha1:
2f63af9ce789c96b5fd2d7f4c64dd1c5d57d3b3b 2578
node-brace-expansion_2.1.7+~1.1.2-1.dsc
bb3f1ed53b210d00e38e2b81e2d60a2f76e0153a 1538
node-brace-expansion_2.1.7+~1.1.2.orig-types-brace-expansion.tar.gz
7316473e6ea590cc139b6dbd9cc180bde1d8e1c8 24429
node-brace-expansion_2.1.7+~1.1.2.orig.tar.gz
88bbd6cc8f80635f960d363a2ddaeb74ba674e54 3448
node-brace-expansion_2.1.7+~1.1.2-1.debian.tar.xz
Checksums-Sha256:
dc21b2b2732c05df53cd98bba3dede24c36a7ca88aaaf4356803ff8e5bf6114a 2578
node-brace-expansion_2.1.7+~1.1.2-1.dsc
6306b27f6ad1bde7ed62f417d9bffc9f62ecd1627234cfa2e67cb363f6580aa5 1538
node-brace-expansion_2.1.7+~1.1.2.orig-types-brace-expansion.tar.gz
14ad0aa72cb2626de214bca6ef2662d7256a7e708efdbcd48500f00ea7fd30bd 24429
node-brace-expansion_2.1.7+~1.1.2.orig.tar.gz
39f0a7ac86f7f6d3d2940a20ee70821ef2f4947846fb36f1feef28b1c024aa0c 3448
node-brace-expansion_2.1.7+~1.1.2-1.debian.tar.xz
Files:
715459a851ae6cfa3a151ab7dcafcb4d 2578 javascript optional
node-brace-expansion_2.1.7+~1.1.2-1.dsc
adb508b32d83eddca9e84f2cee777e5c 1538 javascript optional
node-brace-expansion_2.1.7+~1.1.2.orig-types-brace-expansion.tar.gz
e1088223f33ff1882481833b2839d42c 24429 javascript optional
node-brace-expansion_2.1.7+~1.1.2.orig.tar.gz
c690d90120b575f21021006ab15dbfcc 3448 javascript optional
node-brace-expansion_2.1.7+~1.1.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAnuYACgkQ9tdMp8mZ
7unG9g//Vb+a/IPEWfxPhF+at1zQ+ZrHgIk6iK5XVVzT1Vb43H2Yc7Lhqoim1G0q
kV92J+oZVyvhhcgvrJfZ5+rueJbpONvHEJKKo6hMrdE0Nsloc7fVEqfbgcHjpAVS
vMl7J5NwS5yWNPcB25C9grVdcbgoZ2thefJbV0Ubq5u3eqo59AdEZWbb4lz7icEK
VvnIW4UQ044ZK4obBNfkUyMcBlDWxVCAkFTmCwpsqTujCEBwVXo8q1wwHJMSJKjG
P70pHVCGLcJPmbV+nH5lKhFxUbCleE2KvUi114Qo95cXDooZDvGy2gis/ISCCW1B
iqLRA1R5VR8ds8KV+lrYFt+FltlAHcwnB1NalJEwSvE9lIfCvBwdDGky3xhrOzY3
i3+ObxvGaE2pcdOKJeR+4o0QYfLv3dpuN1e4PgH+v/z5ucE4l1G6gcedzISwfXx5
ShPRzGkl5oT4o7wCfeaKmJzaSsGnf7Umz1XhrnJLhTPYobMtFvU4Xgg4JacV77RC
Y1HjFuNJTtPGqtXEEAWxk1V+rjNcQ1FybjNGr2ifirNWNN5gE0fSYOyXtnetATik
po58Xxu7NoZ95fZIRHCP7nCf1ftzYKu0qVVO27UwXqvaKh26qlV8kP2ZxEsP1Iak
yetPjzDV+Ul53cfxOdgR4o0Xk5QEBBBkhCpAZGNaSK8JiahbxmE=
=whhn
-----END PGP SIGNATURE-----
pgpncVhdZio3j.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel