Medium severity5.3NVD Advisory· Published Mar 30, 2021· Updated Jun 17, 2026
CVE-2018-1109
CVE-2018-1109
Description
A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bracesnpm | >= 2.2.0, < 2.3.1 | 2.3.1 |
Affected products
3- Braces/Bracesdescription
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- snyk.io/vuln/npm:braces:20180219nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-cwfw-4gq5-mrqxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1109ghsaADVISORY
- github.com/micromatch/braces/commit/abdafb0cae1e0c00f184abbadc692f4eaa98f451ghsaWEB
News mentions
0No linked articles in our index yet.