CVE-2026-33671Disposal(jonschlinkert / picomatch)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jonschlinkert picomatch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users to supply glob patterns that are passed to `picomatch` for compilation or matching. In those cases, an attacker can cause excessive CPU consumption and block the Node.js event loop, resulting in a denial of service. Applications that only use trusted, developer-controlled glob patterns are much less likely to be exposed in a security-relevant way. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. If upgrading is not immediately possible, avoid passing untrusted glob patterns to `picomatch`. Possible mitigations include disabling extglob support for untrusted patterns by using `noextglob: true`, rejecting or sanitizing patterns containing nested extglobs or extglob quantifiers such as `+()` and `*()`, enforcing strict allowlists for accepted pattern syntax, running matching in an isolated worker or separate process with time and resource limits, and applying application-level request throttling and input validation for any endpoint that accepts glob patterns.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • picomatch

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disposal: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
picomatch

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 103-2603-3106-01
Signal classification3 categories
Disposal
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
Disposal1
2026-03-311
Disclosure1
2026-06-011
Patch1
Full discourse3 posts
  • MX3 Dev@Mx3Dev
    Patch

    @mem0ai More CVE remediations → langsmith → ^0.6.0 (CVE-2026-45134) → minimatch → ^3.1.3 / ^5.1.8 / ^9.0.7 (3 CVEs) → picomatch → ^2.3.2 (CVE-2026-33671) → path-to-regexp → ^8.4.0 (CVE-2026-4926) → glob → ^10.5.0 (CVE-2025-64756)

    Post summary

    The tweet lists package version updates to remediate several CVEs, indicating available patches.

    1000061
    106 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-33671 impacts picomatch in 3 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/452 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity vulnerability (CVE-2026-33671) affecting picomatch in AWS Lambda base images has been announced, with links to issue discussions but without any PoC, exploit, or patch information disclosed.

    0000026
    32 followersView on X
  • CVE@CVEnew
    Disposal

    CVE-2026-33671 Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processi… https://www.cve.org/CVERecord?id=CVE-2026-33671

    Post summary

    CVE‑2026‑33671 identifies a ReDoS vulnerability in Picomatch prior to versions 4.0.4, 3.0.2, and 2.3.2, but no PoC, exploit, or patch details are provided.

    0000055
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjonschlinkertpicomatch-node.js-

Explore more