In a number of places in ConTeXt's source code, kpse.expand_var is
used to evaluate a texmfcnf configuration variable when
kpse.expand_braces would be the more correct choice. The files that I
have found containing this mistake are
tex/generic/context/luatex/luatex-basics-gen.lua and
tex/generic/context/luatex/luatex-fonts-merged.lua in the ConTeXt
GitHub repository. In both files, kpse.expand_var is used to evaluate
a texmfcnf configuration variable, and the resulting value is then
split into colon- or semicolon-separated components that are then
looped over (similar to how one splits the PATH environment variable
into colon- or semicolon-separated components (depending on the
operating system) and loops over those components to find an
executable).
If a texmfcnf variable, say A, is set to an expression containing
braces, say {a,b}/c, then one clearly intends for the value of A to
expand into a/c:b/c and then split into a/c and b/c. kpse.expand_var
would expand A into {a,b}/c, in which case A would not be split
correctly. kpse.expand_braces would expand A into a/c:b/c, which would
correctly split A into a/c and b/c.
I have attached a patch to correct the bugs.