Red Hat Security Advisory: Red Hat Quay 3.16.6
Quay 3.16.6
AI Analysis
Technical Summary
A flaw in the brace-expansion npm package's expand() function causes exponential-time complexity when processing consecutive non-expanding brace groups. An attacker supplying crafted input to expand(), either directly or via dependencies like minimatch or glob, can cause significant CPU resource consumption and event-loop blocking, resulting in denial of service. The max option does not mitigate this issue as it limits output size but not recursion work. This vulnerability affects multiple Red Hat products that include brace-expansion as a transitive dependency. Red Hat has issued an advisory and recommends upgrading to a fixed version once released.
Potential Impact
The vulnerability leads to denial of service by causing excessive CPU consumption and blocking the event loop in affected applications. This can degrade or halt service availability on systems using vulnerable versions of brace-expansion. There is no impact on confidentiality or integrity. The issue is exploitable remotely without authentication by supplying crafted input to the vulnerable function.
Mitigation Recommendations
Red Hat advises upgrading to a fixed version of the brace-expansion package when it becomes available. Currently, there is no practical mitigation for this vulnerability. Because brace-expansion is typically a transitive dependency pulled in via minimatch and glob, isolating it is difficult. Users should monitor Red Hat advisories for updates and apply patches promptly once released.
Red Hat Security Advisory: Red Hat Quay 3.16.6
Description
Quay 3.16.6
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A flaw in the brace-expansion npm package's expand() function causes exponential-time complexity when processing consecutive non-expanding brace groups. An attacker supplying crafted input to expand(), either directly or via dependencies like minimatch or glob, can cause significant CPU resource consumption and event-loop blocking, resulting in denial of service. The max option does not mitigate this issue as it limits output size but not recursion work. This vulnerability affects multiple Red Hat products that include brace-expansion as a transitive dependency. Red Hat has issued an advisory and recommends upgrading to a fixed version once released.
Potential Impact
The vulnerability leads to denial of service by causing excessive CPU consumption and blocking the event loop in affected applications. This can degrade or halt service availability on systems using vulnerable versions of brace-expansion. There is no impact on confidentiality or integrity. The issue is exploitable remotely without authentication by supplying crafted input to the vulnerable function.
Mitigation Recommendations
Red Hat advises upgrading to a fixed version of the brace-expansion package when it becomes available. Currently, there is no practical mitigation for this vulnerability. Because brace-expansion is typically a transitive dependency pulled in via minimatch and glob, isolating it is difficult. Users should monitor Red Hat advisories for updates and apply patches promptly once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:34478
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a46ecdf27e9c79719440b6f
Added to database: 07/02/2026, 22:57:35 UTC
Last enriched: 08/15/2026, 00:28:49 UTC
Last updated: 10/01/2026, 14:51:04 UTC
Views: 132
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.