CVE-2026-26996Disclosure(minimatch_project / minimatch)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch minimatch_project minimatch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) where N is the number of * characters. With N=15, a single minimatch() call takes ~2 seconds. With N=34, it hangs effectively forever. Any application that passes user-controlled strings to minimatch() as the pattern argument is vulnerable to DoS. This issue has been fixed in version 10.2.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • minimatch

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-02-20); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
minimatch

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-20: 4Mentions · 2026-02-25: 1Mentions · 2026-03-07: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-02-20: 4Technical Details · 2026-02-25: 1Technical Details · 2026-03-07: 102-2002-2503-0705-19
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-204
Disclosure3Patch1
2026-02-251
General1
2026-03-071
Disclosure1
2026-05-191
Patch1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26996 minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression… https://www.cve.org/CVERecord?id=CVE-2026-26996

    Post summary

    The text discloses CVE-2026-26996, a Regular Expression vulnerability affecting minimatch versions 10.2.0 and earlier.

    1001068
    56.4K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    HPE has released a support document listing multiple CVEs affecting their Unified OSS Console Assurance Monitoring, indicating that patches or workarounds are available.

    000001.5K
    6.9K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 minimatch, ReDoS, #CVE-2026-26996 (HIGH) https://dailycve.com/minimatch-redos-cve-2026-26996-high/

    Post summary

    An article announces a high‑severity Regular Expression Denial of Service flaw in minimatch, identified as CVE‑2026‑26996, but no PoC, exploit, or mitigation details are furnished in the brief tweet.

    0000044
    166 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-26996 (CVSS:8.7, HIGH) is Analyzed. minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 ..https://nvd.nist.gov/vuln/detail/CVE-2026-26996 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26996, noting its high CVSS score and that it affects the minimatch utility, but provides no details on exploitation, patches, or PoC.

    0000040
    172 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26996 Regular Expression Denial of Service (ReDoS) Vulnerability in Minimatch <= 10.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26996

    Post summary

    The text announces CVE‑2026‑26996 as a ReDoS flaw present in Minimatch version 10.2.0 and earlier, providing basic technical details but no exploitation or mitigation information.

    0000042
    4.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-26996 impacts minimatch in 10 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/427 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑26996) affecting minimatch in multiple AWS Lambda base images has been disclosed, with links provided for detailed information.

    0000039
    30 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity ReDoS in isaacs minimatch (<10.2.1) can cause app hangs if user input isn't sanitized. Update now to avoid denial of service! 🔧 Details: https://radar.offseq.com/threat/cve-2026-26996-cwe-1333-inefficient-regular-expres-e16ebdd4 #OffSeq #ReDoS #NodeJS https://t.co/QePxMMEiVX

    Post summary

    A high‑severity ReDoS flaw (CVE‑2026‑26996) in isaacs minimatch versions below 10.2.1 can hang applications; users are urged to update immediately to prevent denial of service.

    0000044
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminimatch_projectminimatch-node.js-

Explore more