Inefficient regular expression complexity in minimatch - CVE-2026-27904

 

Inefficient regular expression complexity in minimatch - CVE-2026-27904

Published: April 22, 2026


Vulnerability identifier: #VU126873
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27904
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

minimatch
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
npm
nodejs-devel
nodejs-docs
nodejs-full-i18n
nodejs
nodejs22 (Red Hat package)
nodejs-packaging-bundler
nodejs-packaging
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2026-27904

Install updates from vendor's website.

minimatch - addressed in versions 3.1.4, 4.2.5, 5.1.8, 6.2.2, 7.4.8, 8.0.6, 9.0.7, 10.2.3
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.4
Confluence Data Center - addressed in versions 9.2.21, 10.2.10
Jira Software Data Center - addressed in versions 10.3.22, 11.3.4
nodejs-nodemon - update to 3.0.1-1
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18.25, 4.19.20
npm - update to 10.8.2-1.20.20.2.1
nodejs-devel - update to 20.20.2-1
nodejs-docs - update to 20.20.2-1
nodejs-full-i18n - update to 20.20.2-1
nodejs - update to 20.20.2-1
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs-packaging-bundler - update to 2021.06-6
nodejs-packaging - update to 2021.06-6

External References

Related Security Bulletins