Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2026-27904

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with...

1 affected package

node-minimatch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-minimatch Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27903

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive...

1 affected package

node-minimatch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-minimatch Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-26996

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many...

1 affected package

node-minimatch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-minimatch Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-3517

Medium priority
Fixed

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

1 affected package

node-minimatch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-minimatch Not affected Fixed Fixed
Show less packages

CVE-2016-10540

Medium priority

Some fixes available 2 of 3

Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in the...

1 affected package

node-minimatch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-minimatch Not affected Not affected Not affected
Show less packages