PT-2026-20994 · Minimatch+3 · Minimatch+3

·

CVE-2026-26996

·

Published

2026-02-18

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions minimatch versions 10.2.0 and below
Description The software is susceptible to Regular Expression Denial of Service (ReDoS) when processing glob patterns containing numerous consecutive * wildcards followed by a literal character absent from the input string. Each * translates into a separate [^/]*? regex group, causing exponential backtracking in V8's regex engine upon match failure. The time complexity escalates to O(4^N), where N represents the number of * characters. A single call to minimatch() can take approximately 2 seconds with N=15 and effectively hang with N=34. Applications utilizing user-supplied strings as pattern arguments for the minimatch() function are vulnerable to Denial of Service.
Recommendations Update to version 10.2.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:7080
ALSA-2026:7123
ALSA-2026:7350
ALSA-2026:7670
ALSA-2026:7675
ALSA-2026:7896
ALSA-2026:8339
BDU:2026-07269
CLEANSTART-2026-KN24948
CLEANSTART-2026-ZJ21676
CVE-2026-26996
ECHO-9E51-27FB-FFEC
GHSA-3PPC-4F35-3M26
OPENSUSE-SU-2026:11126-1
OPENSUSE-SU-2026:11178-1
OPENSUSE-SU-2026:20464-1
OPENSUSE-SU-2026:20469-1
OPENSUSE-SU-2026:20502-1
OPENSUSE-SU-2026:20503-1
OPENSUSE-SU-2026:20504-1
OPENSUSE-SU-2026:20532-1
OPENSUSE-SU-2026:21266-1
OPENSUSE-SU-2026:21399-1
RHSA-2026:13508
RHSA-2026:24761
RHSA-2026:7080
RHSA-2026:7123
RHSA-2026:7302
RHSA-2026:7310
RHSA-2026:7350
RHSA-2026:7670
RHSA-2026:7675
RHSA-2026:7896
RHSA-2026:7983
RHSA-2026:8339
RHSA-2026:9711
RHSA-2026:9874
SUSE-SU-2026:1232-1
SUSE-SU-2026:1249-1
SUSE-SU-2026:1250-1
SUSE-SU-2026:1251-1
SUSE-SU-2026:20967-1
SUSE-SU-2026:20973-1
SUSE-SU-2026:20997-1
SUSE-SU-2026:21022-1
SUSE-SU-2026:21023-1
SUSE-SU-2026:21024-1
SUSE-SU-2026:21111-1
SUSE-SU-2026:21141-1
SUSE-SU-2026:21166-1
SUSE-SU-2026:21167-1
SUSE-SU-2026:21168-1
SUSE-SU-2026:21191-1
SUSE-SU-2026:21241-1
SUSE-SU-2026:21245-1
SUSE-SU-2026:21246-1
SUSE-SU-2026:21253-1
SUSE-SU-2026:21256-1
SUSE-SU-2026:21321-1
SUSE-SU-2026:22770-1
SUSE-SU-2026:22837-1

Affected Products

Confluence
Red Os
Rocky Linux
Minimatch