Skip to content

fix CVE-2026-93687 (Uncontrolled Recursion in braces) - #522

Open
wlabu wants to merge 1 commit into
react:mainfrom
wlabu:fix-CVE-2026-93687
Open

wlabu wants to merge 1 commit into
react:mainfrom
wlabu:fix-CVE-2026-93687

Conversation

@wlabu

@wlabu wlabu commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

See:

The underlying problem is the the braces package.
The dependency tree is:

react-strict-dom@0.0.55
  > postcss-react-strict-dom@0.0.55
    > fast-glob@3.3.3
      > micromatch@4.0.8
        > braces@3.0.3

Since braces is no longer being maintained, and the Issue for this CVE has been "locked as spam", it feels like this problem won't be addressed in braces, micromatch, or fast-glob.

So, this PR replaces fast-glob with tinyglobby (npm), a drop-in replacement with a (much) smaller dependency chain.


Notes:

  • the unrelated lock file changes are npm removing 2 stale workspace projects.
  • the expandDirectories addition is because of the migration:
expandDirectories-docs

@meta-cla meta-cla Bot added the cla signed label Sep 29, 2026
@wlabu
wlabu force-pushed the fix-CVE-2026-93687 branch from 4bb7ceb to 2b6ffe0 Compare September 29, 2026 12:24
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

workflow: benchmarks/size

Comparison of minified (terser) and compressed (brotli) size results, measured in bytes. Smaller is better.

Results Base Patch Ratio
react-strict-dom/dist/web/index.js
· compressed 3,251 3,251 1.00
· minified 10,375 10,375 1.00
react-strict-dom/dist/web/runtime.js
· compressed 1,645 1,645 1.00
· minified 4,131 4,131 1.00
react-strict-dom/dist/native/index.js
· compressed 16,850 16,850 1.00
· minified 65,487 65,487 1.00
react-strict-animated/dist/web/index.js
· compressed 6,861 6,861 1.00
· minified 23,486 23,486 1.00
react-strict-animated/dist/native/index.js
· compressed 797 797 1.00
· minified 2,518 2,518 1.00

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

workflow: benchmarks/perf (native)

Comparison of performance test results, measured in operations per second. Larger is better.

Results Base Patch Ratio
css.create
· small 1,142,449 1,152,082 1.01 +
· small with units 481,916 491,753 1.02 +
· small with variables 676,380 663,075 0.98 -
· several small 345,574 345,303 1.00 -
· large 199,600 200,208 1.00 +
· large with polyfills 148,026 147,215 0.99 -
· complex 101,010 101,324 1.00 +
· unsupported 208,316 210,017 1.01 +
css.createTheme
· simple theme 227,029 226,037 1.00 -
· polyfill theme 213,435 212,286 0.99 -

@wlabu wlabu changed the title fix CVE-2026-93687 fix CVE-2026-93687 (Uncontrolled Recursion in braces) Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant