๐Ÿ” CVE Alert

CVE-2026-93687

HIGH 7.5

braces through 3.0.3 Stack Overflow via Deeply Nested Patterns

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

CWE CWE-674
Vendor micromatch
Product braces
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for micromatch braces

Be the first to know when new high vulnerabilities affecting micromatch braces are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

micromatch / braces
0 โ‰ค 3.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/micromatch/braces/issues/70 github.com: https://github.com/micromatch/braces github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/compile.js#L49-L53 github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/expand.js#L102-L105 github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/parse.js#L38-L40 vulncheck.com: https://www.vulncheck.com/advisories/braces-through-3.0.3-stack-overflow-via-deeply-nested-patterns

Credits

Wayde Shi (PayPal Cyber Security Team)