Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 2 advisories

CVE-2026-14257

CVE-2026-14257: 2 tracked advisory records across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

2 advisories
  • Advisory severityHigh7.5

    High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

    CVE-2026-69152Source published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. This issue is due to an incomplete mitigation of CVE-2026-14257. Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue. This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10.0 Extended Update Support
    • Red Hat Enterprise Linux 8
    • Red Hat Enterprise Linux 9.6 Extended Update Support
    • Red Hat Advanced Cluster Security 4.9

    49 more entries in the full advisory.

    Source-reported affected versions
    • < 1.1.18
    • < 2.1.4
    • < 3.0.6
    • < 5.0.9
    Source-reported fixed versions
    • 1.1.18
    • 2.1.4
    • 3.0.6
    • 5.0.9

    46 more entries in the full advisory.

    Mitigation guidance
    • To mitigate this vulnerability, do not pass untrusted input to the expand() function.
  • Advisory severityHigh7.5

    High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function

    CVE-2026-14257Source published Source updated

    Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • 5.0.7
    Source-reported fixed versions
    • nodejs26-main-26.5.0-1.4.hum1
    • grafana12-4-main-12.4.6-0.4.hum1
    • nodejs22-main-22.23.1-2.3.hum1
    • nodejs24-main-24.18.0-0.5.hum1

    3 more entries in the full advisory.

    Mitigation guidance
    • Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery