Skip to content

[GHSA-vfj7-8cjw-p6xm] braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - #10174

Open
VicRobNes wants to merge 1 commit into
VicRobNes/advisory-improvement-10174from
VicRobNes-GHSA-vfj7-8cjw-p6xm
Open

VicRobNes wants to merge 1 commit into
VicRobNes/advisory-improvement-10174from
VicRobNes-GHSA-vfj7-8cjw-p6xm

Conversation

@VicRobNes

@VicRobNes VicRobNes commented Oct 4, 2026 •

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • Description
  • References

Comments
NDC Inc. checked the published npm 3.0.3 package and its public source. The proposed text names all three affected public methods. It also makes process termination conditional on an unhandled error. In isolated tests on Node.js 22.23.3, a 9,000-character nested pattern caused stack errors. The affected methods were compile, expand, and stringify.

A direct, unhandled expand call exited with status 1. On Node.js 24.21.0, the same direct call exited in 19 of 20 trials at 10,000 characters. It exited in 2 of 20 trials at 9,000 characters. The variable threshold supports the runtime qualification.

The new references show the public methods, the input limit, and the stringify walker. No released fixed version was found. Open upstream patch proposals remain unmerged and are not listed as patched versions.

Submission note: GitHub's improvement form also removed the existing CVSS v3 vector. NDC Inc. did not assess or request a severity change. Please retain the current CVSS v3 metadata when reviewing this description and its references.

Copilot AI balanced review requested due to automatic review settings October 4, 2026 17:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions
github-actions Bot changed the base branch from main to VicRobNes/advisory-improvement-10174 October 4, 2026 17:55
@VicRobNes

Copy link
Copy Markdown
Author

Curator note: GitHub's advisory improvement form removed the existing CVSS v3 vector in the generated changes. NDC Inc. did not assess or request a change to the severity score. Please keep the current CVSS v3 vector and score when you review this request. Our research supports the updated description and references.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants