CVE-2026-27904Disclosure(minimatch_project / minimatch)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch minimatch_project minimatch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • minimatch

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
minimatch

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2602-2703-0305-19
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-02-272
Disclosure1General1
2026-03-031
Disclosure1
2026-05-191
Patch1
Full discourse6 posts
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    The content lists several CVEs and references an HPE support advisory, implying patches or mitigations are available, but provides no PoC, exploit, or technical details.

    000001.5K
    6.9K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27904 (CVSS:7.5, HIGH) is Analyzed. minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version..https://nvd.nist.gov/vuln/detail/CVE-2026-27904 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27904, noting its CVSS score and that it involves the minimatch utility, but provides no details on exploitation, patches, or PoC.

    0000023
    173 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-27904 impacts minimatch in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/432 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A newly identified high‑severity vulnerability, CVE‑2026‑27904, affects the minimatch component in four AWS Lambda base images, with issue details linked in the post.

    0000069
    30 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-27904: The Infinite Loop of Doom: Unpacking CVE-2026-27904 in Minimatch Minimatch, the ubiquitous JavaScript glob matcher that likely powers your entire build pipeline, has a nasty habit of choking on its own logic. A specifically crafted 'ex... https://cvereports.com/reports/CVE-2026-27904

    Post summary

    The text announces CVE-2026-27904, noting an infinite-loop flaw in Minimatch, but lacks details on PoC, exploit, patch, or technical specifics.

    0000051
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27904 minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.… https://www.cve.org/CVERecord?id=CVE-2026-27904

    Post summary

    The text references CVE-2026-27904 and lists affected versions of minimatch, but provides no further details on exploitation, patches, or technical specifics.

    00000123
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27904 Catastrophic Regex Backtracking Vulnerability in Minimatch Glob Matching Library https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27904

    Post summary

    A new CVE-2026-27904 is disclosed, describing a catastrophic regex backtracking flaw in the Minimatch glob matching library, with no PoC, exploit, or patch details provided.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminimatch_projectminimatch-node.js-

Explore more