Skip to content

[GHSA-vfj7-8cjw-p6xm] braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - #10127

Open
naveensharmatech wants to merge 1 commit into
naveensharmatech/advisory-improvement-10127from
naveensharmatech-GHSA-vfj7-8cjw-p6xm
Open

naveensharmatech wants to merge 1 commit into
naveensharmatech/advisory-improvement-10127from
naveensharmatech-GHSA-vfj7-8cjw-p6xm

Conversation

@naveensharmatech

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

Copilot AI balanced review requested due to automatic review settings October 3, 2026 13:31
@github-actions
github-actions Bot changed the base branch from main to naveensharmatech/advisory-improvement-10127 October 3, 2026 13:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused metadata change is valid and introduces no identified issues.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the braces denial-of-service advisory’s severity metadata.

Changes:

  • Removes the CVSS v3 vector while retaining CVSS v4.
  • Advances the advisory modification timestamp.
File Description
GHSA-vfj7-8cjw-p6xm.json Updates severity and modification metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants