Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.webjars.npm:brace-expansion to version 5.0.12 or higher.
org.webjars.npm:brace-expansion is a WebJar for brace-expansion.
Affected versions of this package are vulnerable to Uncontrolled Recursion via two distinct stack-exhaustion paths in parseCommaParts. In the first, the function recurses on the remainder of the string once per brace group, so a chain of approximately 7,000 groups (~29 KB of input) exhausts the native call stack and throws a RangeError. In the second, push.apply passes one argument per element, meaning a single large comma-separated array inside a brace group overflows the stack at a recursion depth of exactly one, requiring roughly 125,000 comma-separated elements. Neither the max nor maxLength options can bound either path because the crash occurs during parsing, before any expansion takes place.