Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3ppc-4f35-3m26 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
Sat, 21 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Minimatch Project
Minimatch Project minimatch |
|
| CPEs | cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Minimatch Project
Minimatch Project minimatch |
|
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Isaacs
Isaacs minimatch |
|
| Vendors & Products |
Isaacs
Isaacs minimatch |
Fri, 20 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) where N is the number of * characters. With N=15, a single minimatch() call takes ~2 seconds. With N=34, it hangs effectively forever. Any application that passes user-controlled strings to minimatch() as the pattern argument is vulnerable to DoS. This issue has been fixed in version 10.2.1. | |
| Title | minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-20T15:34:15.151Z
Reserved: 2026-02-17T01:41:24.607Z
Link: CVE-2026-26996
Updated: 2026-02-20T15:31:37.900Z
Status : Analyzed
Published: 2026-02-20T03:16:01.620
Modified: 2026-03-06T21:32:10.650
Link: CVE-2026-26996
OpenCVE Enrichment
Updated: 2026-04-17T17:45:24Z
Github GHSA