CVE-2026-93687
braces through 3.0.3 Stack Overflow via Deeply Nested Patterns
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
| CWE | CWE-674 |
| Vendor | micromatch |
| Product | braces |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for micromatch braces
Be the first to know when new high vulnerabilities affecting micromatch braces are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
micromatch / braces
0 โค 3.0.3
References
github.com: https://github.com/micromatch/braces/issues/70 github.com: https://github.com/micromatch/braces github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/compile.js#L49-L53 github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/expand.js#L102-L105 github.com: https://github.com/micromatch/braces/blob/3.0.3/lib/parse.js#L38-L40 vulncheck.com: https://www.vulncheck.com/advisories/braces-through-3.0.3-stack-overflow-via-deeply-nested-patterns
Credits
Wayde Shi (PayPal Cyber Security Team)