Skip to main content
Version: v1.4.x

CVE-2026-102278

CVE Details​

Visit the official vulnerability details page for CVE-2026-102278 to learn more.

Initial Publication​

09/28/2026

Last Update​

09/28/2026

Third Party Dependency​

brace-expansion

NIST CVE Summary​

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11.

CVE Severity​

7.5

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Received

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.