Duplicate Advisory: Regular Expression Denial of Service in braces
Low severity
GitHub Reviewed
Published
Jun 6, 2019
to the GitHub Advisory Database
•
Updated Feb 3, 2026
Withdrawn
This advisory was withdrawn on Feb 3, 2026
Description
Reviewed
Jun 6, 2019
Published to the GitHub Advisory Database
Jun 6, 2019
Last updated
Feb 3, 2026
Withdrawn
Feb 3, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-cwfw-4gq5-mrqx. This link is maintained to preserve external references.
Original Description
Versions of
bracesprior to 2.3.1 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.Recommendation
Upgrade to version 2.3.1 or higher.
References