High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
This high-severity Red Hat Linux advisory covers CVE-2026-69152 and CVE-2026-14257 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations. This bulletin covers 2 CVEs; its score, affected versions and guidance may apply to different issues within that bulletin.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop.
The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
This issue is due to an incomplete mitigation of CVE-2026-14257. Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue.
This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Security 4.9; and 49 more.
- < 1.1.18
- < 2.1.4
- < 3.0.6
- < 5.0.9
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
- 1.1.18
- 2.1.4
- 3.0.6
- 5.0.9
- nodejs-nodemon-0:3.1.14-3.el10_2
- nodejs22-1:22.23.1-6.el10_2
- rh-podman-desktop-0:1.1.2-1.el10_2
- nodejs24-1:24.18.0-5.el10_2
- nodejs-nodemon-0:3.1.14-3.el10_0
- nodejs22-1:22.23.2-1.el10_0
- nodejs:24-8100020260807112957.6d880403
- nodejs:22-8100020260807115047.6d880403
- nodejs:22-9080020260806135640.rhel9
- nodejs:24-9080020260806135511.rhel9
- nodejs:22-9060020260901085634.rhel9
- advanced-cluster-security/rhacs-main-rhel8:1787584486
- advanced-cluster-security/rhacs-main-rhel8:1787584487
- advanced-cluster-security/rhacs-main-rhel9:1787584498
- ansible-automation-platform/automation-portal:1787047114
- ansible-automation-platform/automation-portal:1787047188
- ansible-automation-platform/bootc-automation-portal-rhel9:1788943531
- ansible-automation-platform-25/lightspeed-rhel8:1787229385
- ansible-automation-platform-26/lightspeed-rhel9:1787244079
- rhdh/red-hat-developer-hub-backstage-plugin-lightspeed:1788187400
- rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1788186854
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator:1788186989
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1788187326
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1788187449
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets:1788186625
- rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1788187032
- rhdh/rhdh-hub-rhel9:1788286049
- discovery/discovery-ui-rhel9:1786634825
- grafana13-1-main-13.1.1-0.5.1.hum1
- grafana12-4-main-12.4.6-0.4.hum1
- grafana13-1-main-13.1.1-0.5.2.hum1
- nodejs24-main-24.18.1-0.2.1.hum1
- nodejs26-main-26.7.0-1.5.2.hum1
- nodejs22-main-22.23.2-2.3.2.hum1
- rhoai/odh-dashboard-rhel9:1788312226
- rhoai/odh-mod-arch-model-registry-rhel9:1788312157
- rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787801527
- rhoai/odh-dashboard-rhel9:1787347991
- rhoai/odh-mod-arch-automl-rhel9:1787250508
- rhoai/odh-mod-arch-autorag-rhel9:1787251550
- RHSA-2026:52841
- RHSA-2026:55541
- RHSA-2026:57590
- RHSA-2026:58819
- RHSA-2026:61374
- RHSA-2026:64817
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
Mitigation checklist
- To mitigate this vulnerability, do not pass untrusted input to the expand() function.
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.