Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

This high-severity Red Hat Linux advisory covers CVE-2026-69152 and CVE-2026-14257 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations. This bulletin covers 2 CVEs; its score, affected versions and guidance may apply to different issues within that bulletin.

CVE-2026-69152 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop.

The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

This issue is due to an incomplete mitigation of CVE-2026-14257. Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue.

This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Security 4.9; and 49 more.

Affected versions
  • < 1.1.18
  • < 2.1.4
  • < 3.0.6
  • < 5.0.9

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Fixed versions
  • 1.1.18
  • 2.1.4
  • 3.0.6
  • 5.0.9
  • nodejs-nodemon-0:3.1.14-3.el10_2
  • nodejs22-1:22.23.1-6.el10_2
  • rh-podman-desktop-0:1.1.2-1.el10_2
  • nodejs24-1:24.18.0-5.el10_2
  • nodejs-nodemon-0:3.1.14-3.el10_0
  • nodejs22-1:22.23.2-1.el10_0
  • nodejs:24-8100020260807112957.6d880403
  • nodejs:22-8100020260807115047.6d880403
  • nodejs:22-9080020260806135640.rhel9
  • nodejs:24-9080020260806135511.rhel9
  • nodejs:22-9060020260901085634.rhel9
  • advanced-cluster-security/rhacs-main-rhel8:1787584486
  • advanced-cluster-security/rhacs-main-rhel8:1787584487
  • advanced-cluster-security/rhacs-main-rhel9:1787584498
  • ansible-automation-platform/automation-portal:1787047114
  • ansible-automation-platform/automation-portal:1787047188
  • ansible-automation-platform/bootc-automation-portal-rhel9:1788943531
  • ansible-automation-platform-25/lightspeed-rhel8:1787229385
  • ansible-automation-platform-26/lightspeed-rhel9:1787244079
  • rhdh/red-hat-developer-hub-backstage-plugin-lightspeed:1788187400
  • rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1788186854
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator:1788186989
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1788187326
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1788187449
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets:1788186625
  • rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1788187032
  • rhdh/rhdh-hub-rhel9:1788286049
  • discovery/discovery-ui-rhel9:1786634825
  • grafana13-1-main-13.1.1-0.5.1.hum1
  • grafana12-4-main-12.4.6-0.4.hum1
  • grafana13-1-main-13.1.1-0.5.2.hum1
  • nodejs24-main-24.18.1-0.2.1.hum1
  • nodejs26-main-26.7.0-1.5.2.hum1
  • nodejs22-main-22.23.2-2.3.2.hum1
  • rhoai/odh-dashboard-rhel9:1788312226
  • rhoai/odh-mod-arch-model-registry-rhel9:1788312157
  • rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787801527
  • rhoai/odh-dashboard-rhel9:1787347991
  • rhoai/odh-mod-arch-automl-rhel9:1787250508
  • rhoai/odh-mod-arch-autorag-rhel9:1787251550
  • RHSA-2026:52841
  • RHSA-2026:55541
  • RHSA-2026:57590
  • RHSA-2026:58819
  • RHSA-2026:61374
  • RHSA-2026:64817

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this vulnerability, do not pass untrusted input to the expand() function.

Official advisory · high-confidence parse· fetched 26 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.