CVE-2026-27903Disclosure(minimatch_project / minimatch)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch minimatch_project minimatch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call to the default `minimatch()` API stalls for roughly 5 seconds. With k=13, it exceeds 15 seconds. No memoization or call budget exists to bound this behavior. Any application where an attacker can influence the glob pattern passed to `minimatch()` is vulnerable. The realistic attack surface includes build tools and task runners that accept user-supplied glob arguments (ESLint, Webpack, Rollup config), multi-tenant systems where one tenant configures glob-based rules that run in a shared process, admin or developer interfaces that accept ignore-rule or filter configuration as globs, and CI/CD pipelines that evaluate user-submitted config files containing glob patterns. An attacker who can place a crafted pattern into any of these paths can stall the Node.js event loop for tens of seconds per invocation. The pattern is 56 bytes for a 5-second stall and does not require authentication in contexts where pattern input is part of the feature. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • minimatch

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
minimatch

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 102-2602-2703-0305-19
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-02-272
Disclosure2
2026-03-031
Disclosure1
2026-05-191
Patch1
Full discourse6 posts
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    HPE released patch rev.1 (HPESBNW05056) for a series of vulnerabilities, including CVE‑2025‑12758, CVE‑2025‑64945, CVE‑2026‑27699, CVE‑2026‑27601, CVE‑2026‑27903, CVE‑2026‑27904, CVE‑2026‑26996, and CVE‑2026‑25639.

    000001.5K
    6.9K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27903 (CVSS:7.5, HIGH) is Analyzed. minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version..https://nvd.nist.gov/vuln/detail/CVE-2026-27903 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces analysis of CVE-2026-27903, noting its CVSS score and the affected library minimatch, but provides no details on exploitation, patches, or PoC.

    0000021
    173 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-27903 impacts minimatch in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/431 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2026‑27903) affecting minimatch in AWS Lambda base images has been reported, with references to issue trackers but no PoC, exploit code, or patch details provided.

    0000043
    30 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27903: Minimatch Mayhem: How Two Asterisks Can Kill Your Node.js Server A high-severity Regular Expression Denial of Service (ReDoS) vulnerability exists in the popular `minimatch` library, affecting millions of Node.js projects. The flaw lie... https://cvereports.com/reports/CVE-2026-27903

    Post summary

    CVE‑2026‑27903 is a high‑severity ReDoS flaw in the minimatch library, affecting many Node.js projects. The report provides technical details but no exploit, patch, or evidence of active exploitation.

    0000050
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27903 minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.… https://www.cve.org/CVERecord?id=CVE-2026-27903

    Post summary

    The text references CVE-2026-27903 and lists affected versions but provides no further details on exploitation, patches, or technical specifics.

    00000120
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27903 Denial of Service via Unbounded Recursive Backtracking in Minimat... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27903 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE (CVE-2026-27903) is disclosed as a denial‑of‑service vulnerability caused by unbounded recursive backtracking in Minimat, with a link to details but no PoC, exploit, patch, or active exploitation mentioned.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminimatch_projectminimatch-node.js-

Explore more