CVE-2026-33750: brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Published Mar 26, 2026
·
Updated

Impact

A brace pattern with a zero step value (e.g., {1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory.

The loop in question:

https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184

test() is one of

https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113

The increment is computed as Math.abs(0) = 0, so the loop variable never advances. On a test machine, the process hangs for about 3.5 seconds and allocates roughly 1.9 GB of memory before throwing a RangeError. Setting max to any value has no effect because the limit is only checked at the output combination step, not during sequence generation.

This affects any application that passes untrusted strings to expand(), or by error sets a step value of 0. That includes tools built on minimatch/glob that resolve patterns from CLI arguments or config files. The input needed is just 10 bytes.

Patches

Upgrade to versions - 5.0.5+

A step increment of 0 is now sanitized to 1, which matches bash behavior.

Workarounds

Sanitize strings passed to expand() to ensure a step value of 0 is not used.

Other sources

brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Microsoft

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., {1..2..0}) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to expand() to ensure a step value of 0 is not used.

MITRE

Affected Software

11 affected componentsFixes available
npm/brace-expansion<1.1.13
1.1.13
npm/brace-expansion>=2.0.0<2.0.3
2.0.3
npm/brace-expansion>=3.0.0<3.0.2
3.0.2
npm/brace-expansion>=4.0.0<5.0.5
5.0.5
Microsoft cbl2 nodejs18 18.20.3-12
Microsoft cbl2 nodejs18 18.20.3-11
juliangruber Brace-expansion Node.js<1.1.13
juliangruber Brace-expansion Node.js>=2.0.0<2.0.3
juliangruber Brace-expansion Node.js>=3.0.0<3.0.2
juliangruber Brace-expansion Node.js>=5.0.0<5.0.5
IBM watsonx.data intelligence<=5.2.2, 5.3.0, 5.3.1, 5.3.1-patch-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 1.1.13
  2. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 2.0.3
  3. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 3.0.2
  4. Upgrade

    Upgrade npm/brace-expansion to a version that resolves this vulnerability.

    Fixed in 5.0.5
  5. Upgrade

    Upgrade brace-expansion to a version that resolves this vulnerability.

    Fixed in 5.0.5
  6. Upgrade

    Upgrade brace-expansion to a version that resolves this vulnerability.

    Fixed in 3.0.2
  7. Upgrade

    Upgrade brace-expansion to a version that resolves this vulnerability.

    Fixed in 2.0.3
  8. Upgrade

    Upgrade brace-expansion to a version that resolves this vulnerability.

    Fixed in 1.1.13
  9. Configuration

    As a workaround, sanitize strings passed to `expand()` so a step value of `0` is not used (0 should be converted to `1`).

    brace-expansion (expand function) brace pattern zero step value = sanitize step value so 0 is not used (treat 0 as 1)

Event History

Mar 26, 2026
Advisory Published
via GitHub·06:29 PM
Data Sourced
via GitHub·06:29 PM
DescriptionSeverityWeaknessAffected Software
Mar 27, 2026
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyAffected Software
Mar 31, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
SeverityAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Jun 24, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33750?

CVE-2026-33750 is assigned a high severity due to its potential to cause applications to hang indefinitely and exhaust system memory.

2

How do I fix CVE-2026-33750?

To fix CVE-2026-33750, upgrade the brace-expansion package to versions greater than 5.0.5.

3

What causes the vulnerability CVE-2026-33750?

CVE-2026-33750 is caused by a brace pattern with a zero step value, leading to an infinite loop during sequence generation.

4

Who is affected by CVE-2026-33750?

Users of the brace-expansion package version 5.0.5 and below are affected by CVE-2026-33750.

5

Is CVE-2026-33750 a code execution vulnerability?

CVE-2026-33750 is not a code execution vulnerability, but rather a resource exhaustion issue that leads to unresponsive applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203