PT-2026-20994 · Minimatch+2 · Minimatch+2

Akshayjaing

·

Published

2026-02-18

·

Updated

2026-05-21

·

CVE-2026-26996

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions minimatch versions 10.2.0 and below
Description The software is susceptible to Regular Expression Denial of Service (ReDoS) when processing glob patterns containing numerous consecutive * wildcards followed by a literal character absent from the input string. Each * translates into a separate [^/]*? regex group, causing exponential backtracking in V8's regex engine upon match failure. The time complexity escalates to O(4^N), where N represents the number of * characters. A single call to minimatch() can take approximately 2 seconds with N=15 and effectively hang with N=34. Applications utilizing user-supplied strings as pattern arguments for the minimatch() function are vulnerable to Denial of Service.
Recommendations Update to version 10.2.1 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2026:7080
ALSA-2026:7123
ALSA-2026:7350
ALSA-2026:7670
ALSA-2026:7675
ALSA-2026:7896
ALSA-2026:8339
BDU:2026-07269
CVE-2026-26996
GHSA-3PPC-4F35-3M26
OPENSUSE-SU-2026:20464-1
OPENSUSE-SU-2026:20469-1
OPENSUSE-SU-2026:20502-1
OPENSUSE-SU-2026:20503-1
OPENSUSE-SU-2026:20504-1
OPENSUSE-SU-2026:20532-1
RHSA-2026:13508
RHSA-2026:7080
RHSA-2026:7123
RHSA-2026:7302
RHSA-2026:7310
RHSA-2026:7350
RHSA-2026:7670
RHSA-2026:7675
RHSA-2026:7896
RHSA-2026:7983
RHSA-2026:8339
RHSA-2026:9711
RHSA-2026:9874
SUSE-SU-2026:1232-1
SUSE-SU-2026:1249-1
SUSE-SU-2026:1250-1
SUSE-SU-2026:1251-1
SUSE-SU-2026:20967-1
SUSE-SU-2026:20973-1
SUSE-SU-2026:20997-1
SUSE-SU-2026:21022-1
SUSE-SU-2026:21023-1
SUSE-SU-2026:21024-1
SUSE-SU-2026:21111-1
SUSE-SU-2026:21141-1
SUSE-SU-2026:21166-1
SUSE-SU-2026:21167-1
SUSE-SU-2026:21168-1
SUSE-SU-2026:21191-1
SUSE-SU-2026:21241-1
SUSE-SU-2026:21245-1
SUSE-SU-2026:21246-1
SUSE-SU-2026:21253-1
SUSE-SU-2026:21256-1
SUSE-SU-2026:21321-1

Affected Products

Red Os
Rocky Linux
Minimatch