Inefficient regular expression complexity in minimatch - CVE-2026-26996
Published: February 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions within "minimatch" function. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
Fusion Content-Aware Storage
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite - IoT Component
Rational Performance Tester
DevOps Test Performance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Big SQL
Maximo Scheduler Optimizer
InfoSphere Optim Archive Viewer
IBM Fusion HCI
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Confluence Data Center
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
cockpit-tukit
nodejs-nodemon
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs22 (Red Hat package)
nodejs24 (Red Hat package)
cockpit-podman
cockpit-machines
cockpit-system
cockpit-ws-debuginfo
cockpit-ws
cockpit-bridge-debuginfo
cockpit-debugsource
cockpit-debuginfo
cockpit-bridge
cockpit
nodejs-packaging-bundler
nodejs-packaging
Event Streams
IBM QRadar Data Synchronization App
IBM Security SOAR
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2026-26996
Fusion Content-Aware Storage - update to 1.1.5
Cognos Analytics Mobile (iOS) - update to 1.1.26
Cognos Analytics Mobile (Android) - update to 1.1.26
IBM Fusion HCI - update to 2.13.0
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.18-sc2, 4.3.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - IoT Component - addressed in versions 8.7.32, 8.8.29, 9.0.18, 9.1.9
Confluence Data Center - addressed in versions 9.2.21, 10.2.10
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.22, 16.1.3.4
IBM Security SOAR - update to 51.0.9.1
cockpit-tukit - update to 0.0.3~git14.ff11a9a-150300.1.9.1
nodejs-nodemon - update to 3.0.1-1
IBM QRadar Data Synchronization App - update to 4.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.66, 4.18.48
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
Db2 Big SQL - update to 8.3.1 patch 4
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
npm - update to 10.8.2-1.20.20.2.1
InfoSphere Optim Archive Viewer - update to 11.7.0.14
nodejs-docs - update to 20.20.2-1
nodejs-full-i18n - update to 20.20.2-1
nodejs-devel - update to 20.20.2-1
nodejs - update to 20.20.2-1
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
cockpit-podman - update to 33-150300.6.9.1
cockpit-machines - update to 249.1-150300.5.6.1
cockpit-system - update to 251.3-150300.6.9.1
cockpit-ws-debuginfo - update to 251.3-150300.6.9.1
cockpit-ws - update to 251.3-150300.6.9.1
cockpit-bridge-debuginfo - update to 251.3-150300.6.9.1
cockpit-debugsource - update to 251.3-150300.6.9.1
cockpit-debuginfo - update to 251.3-150300.6.9.1
cockpit-bridge - update to 251.3-150300.6.9.1
cockpit - update to 251.3-150300.6.9.1
nodejs-packaging-bundler - update to 2021.06-6
nodejs-packaging - update to 2021.06-6
External References
Related Security Bulletins
- Multiple vulnerabilities in minimatch
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- IBM Security SOAR update for minimatch
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- SUSE update for cockpit
- SUSE update for cockpit-podman
- SUSE update for cockpit-machines
- SUSE update for cockpit-tukit
- IBM DevOps Test Performance update for minimatch
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Anolis OS update for nodejs:20 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 10 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- IBM Watson Discovery Cartridge update for minimatch
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for minimatch
- IBM Maximo Scheduler Optimizer update for minimatch
- IBM Big SQL on Cloud Pak for Data update for minimatch
- Multiple vulnerabilities in IBM Cognos Analytics Mobile
- IBM InfoSphere Optim Archive Viewer update for minimatch
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage