CVE-2018-1109

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1547272 Issue Tracking Patch Third Party Advisory
https://snyk.io/vuln/npm:braces:20180219 Exploit Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1547272 Issue Tracking Patch Third Party Advisory
https://snyk.io/vuln/npm:braces:20180219 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:braces_project:braces:*:*:*:*:*:node.js:*:*

History

01 Dec 2025, 15:15

Type Values Removed Values Added
Summary (en) A vulnerability was found in Braces versions prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks. (en) A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

Information

Published : 2021-03-30 02:15

Updated : 2025-12-01 15:15


NVD link : CVE-2018-1109

Mitre link : CVE-2018-1109

CVE.ORG link : CVE-2018-1109


JSON object : View

Products Affected

braces_project

  • braces
CWE
CWE-185

Incorrect Regular Expression

CWE-400

Uncontrolled Resource Consumption