Inefficient regular expression complexity in minimatch - CVE-2026-26996

 

Inefficient regular expression complexity in minimatch - CVE-2026-26996

Published: February 23, 2026


Vulnerability identifier: #VU123140
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26996
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions within "minimatch" function. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

minimatch
Fusion Content-Aware Storage
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite - IoT Component
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Big SQL
Maximo Scheduler Optimizer
InfoSphere Optim Archive Viewer
IBM Fusion HCI
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Confluence Data Center
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cockpit-tukit
nodejs-nodemon
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs22 (Red Hat package)
nodejs24 (Red Hat package)
cockpit-podman
cockpit-machines
cockpit-system
cockpit-ws-debuginfo
cockpit-ws
cockpit-bridge-debuginfo
cockpit-debugsource
cockpit-debuginfo
cockpit-bridge
cockpit
nodejs-packaging-bundler
nodejs-packaging
Event Streams
IBM QRadar Data Synchronization App
IBM Security SOAR
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2026-26996

Install updates from vendor's website.

minimatch - addressed in versions 3.1.3, 4.2.4, 5.1.7, 6.2.1, 7.4.7, 8.0.5, 9.0.6, 10.2.1
Fusion Content-Aware Storage - update to 1.1.5
Cognos Analytics Mobile (iOS) - update to 1.1.26
Cognos Analytics Mobile (Android) - update to 1.1.26
IBM Fusion HCI - update to 2.13.0
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.18-sc2, 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - IoT Component - addressed in versions 8.7.32, 8.8.29, 9.0.18, 9.1.9
Confluence Data Center - addressed in versions 9.2.21, 10.2.10
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.22, 16.1.3.4
IBM Security SOAR - update to 51.0.9.1
cockpit-tukit - update to 0.0.3~git14.ff11a9a-150300.1.9.1
nodejs-nodemon - update to 3.0.1-1
IBM QRadar Data Synchronization App - update to 4.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.66, 4.18.48
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
Db2 Big SQL - update to 8.3.1 patch 4
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
npm - update to 10.8.2-1.20.20.2.1
InfoSphere Optim Archive Viewer - update to 11.7.0.14
nodejs-docs - update to 20.20.2-1
nodejs-full-i18n - update to 20.20.2-1
nodejs-devel - update to 20.20.2-1
nodejs - update to 20.20.2-1
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
cockpit-podman - update to 33-150300.6.9.1
cockpit-machines - update to 249.1-150300.5.6.1
cockpit-system - update to 251.3-150300.6.9.1
cockpit-ws-debuginfo - update to 251.3-150300.6.9.1
cockpit-ws - update to 251.3-150300.6.9.1
cockpit-bridge-debuginfo - update to 251.3-150300.6.9.1
cockpit-debugsource - update to 251.3-150300.6.9.1
cockpit-debuginfo - update to 251.3-150300.6.9.1
cockpit-bridge - update to 251.3-150300.6.9.1
cockpit - update to 251.3-150300.6.9.1
nodejs-packaging-bundler - update to 2021.06-6
nodejs-packaging - update to 2021.06-6

External References

Related Security Bulletins