Package
kibana-9.4
Component
braces
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The recursive AST walkers lack depth guards, so deeply nested brace patterns can exhaust the call stack and crash the Node.js process. The affected range covers every release through 3.0.3, which is the latest published version, and no patched release exists. The upstream fix is not yet merged or released, and the project has had no release since 3.0.3. The package remains pending until a fixed release is published and can be adopted.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-93687 https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
Status