Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-13149] Denial of Service due to exponential-time complexity

This high-severity Red Hat Linux advisory covers CVE-2026-13149 affecting Cryostat 4 on RHEL 9, Red Hat AMQ Broker 7.13.6, Red Hat AMQ Broker 7.14.1.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-13149 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups.

An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.

An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This can result in a Denial of Service (DoS) for the affected system.

A flaw was found in brace-expansion, a widely-used npm package for expanding brace sequences. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness: CWE-1333.

Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Enterprise Linux 10.0 Extended Update Support; and 48 more.

Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Security 4.9; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 44 more.

Affected versions
  • 5.0.6

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Fixed versions
  • cryostat/cryostat-grafana-dashboard-rhel9:4.2.0-13
  • brace-expansion
  • nodejs-nodemon-0:3.1.14-2.el10_2
  • nodejs22-1:22.23.1-4.el10_2
  • nodejs24-1:24.18.0-3.el10_2
  • rh-podman-desktop-0:1.1.2-1.el10_2
  • nodejs-nodemon-0:3.1.14-2.el10_0
  • nodejs22-1:22.23.1-3.el10_0
  • nodejs:22-8100020260724100938.6d880403
  • nodejs:24-8100020260724132848.6d880403
  • nodejs:24-9080020260721131809.rhel9
  • nodejs:22-9080020260721131741.rhel9
  • nodejs:22-9060020260804140259.rhel9
  • advanced-cluster-security/rhacs-main-rhel8:1785413210
  • advanced-cluster-security/rhacs-main-rhel8:1785420959
  • advanced-cluster-security/rhacs-main-rhel9:1785415868
  • ansible-automation-platform/automation-portal:1784622951
  • ansible-automation-platform/bootc-automation-portal-rhel9:1786006573
  • ansible-automation-platform-25/lightspeed-rhel8:1785430174
  • ansible-automation-platform-26/gateway-rhel9:1785780020
  • ansible-automation-platform-26/lightspeed-rhel9:1785775360
  • ansible-automation-platform-27/gateway-rhel9:1785435970
  • rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1785332487
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825
  • rhdh/rhdh-hub-rhel9:1785411652
  • rhdh/rhdh-hub-rhel9:1785972843
  • rhem/flightctl-ui-ocp-rhel10:1789486226
  • rhem/flightctl-ui-rhel10:1789486181
  • rhem/flightctl-ui-ocp-rhel9:1789486446
  • rhem/flightctl-ui-ocp-rhel10:1789485920
  • rhem/flightctl-ui-rhel10:1789488111
  • rhem/flightctl-ui-ocp-rhel9:1789486476
  • rhem/flightctl-ui-rhel9:1789486750
  • nodejs26-main-26.4.0-1.3.hum1
  • nodejs24-main-24.18.0-0.2.hum1
  • nodejs22-main-22.23.1-2.hum1
  • nodejs26-main-26.5.0-1.4.hum1
  • nodejs26-main-26.7.0-1.5.1.hum1
  • rhmtc/openshift-migration-ui-rhel8:1783690532
  • mta/mta-ui-rhel9:1785169013
  • RHSA-2026:48151
  • RHSA-2026:66545
  • RHSA-2026:66488
  • RHSA-2026:48032
  • RHSA-2026:48033
  • RHSA-2026:48034
  • RHSA-2026:57590
  • RHSA-2026:52394
  • RHSA-2026:53298
  • RHSA-2026:47059

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.