CVE-2026-14257
CVE-2026-14257: 2 tracked advisory records across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
2 advisories- Advisory severityHigh7.5
High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69152Source published Source updated
This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9. This issue is due to an incomplete mitigation of CVE-2026-14257. Any applications that pass user-controlled input to the `expand()` function are vulnerable to this issue. This flaw can result in an excessive consumption of memory that eventually terminates the process or blocks the event loop, both causing a denial of service. As this…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9.6 Extended Update Support
- Red Hat Advanced Cluster Security 4.9
49 more entries in the full advisory.
- Source-reported affected versions
- < 1.1.18
- < 2.1.4
- < 3.0.6
- < 5.0.9
- Source-reported fixed versions
- 1.1.18
- 2.1.4
- 3.0.6
- 5.0.9
46 more entries in the full advisory.
- Mitigation guidance
- To mitigate this vulnerability, do not pass untrusted input to the expand() function.
- Advisory severityHigh7.5
High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function
CVE-2026-14257Source published Source updated
Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.
- Related products — impact not confirmed
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 5.0.7
- Source-reported fixed versions
- nodejs26-main-26.5.0-1.4.hum1
- grafana12-4-main-12.4.6-0.4.hum1
- nodejs22-main-22.23.1-2.3.hum1
- nodejs24-main-24.18.0-0.5.hum1
3 more entries in the full advisory.
- Mitigation guidance
- Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.