Inefficient Algorithmic Complexity in minimatch - CVE-2026-27903
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in matchOne() when processing glob patterns containing multiple non-adjacent GLOBSTAR segments. A remote attacker can supply a specially crafted glob pattern to cause a denial of service.
The issue is triggered on non-matching input and can stall the Node.js event loop while the recursive call tree is fully explored.
Affected software
Fusion Content-Aware Storage
IBM Fusion HCI
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
IBM QRadar Data Synchronization App
How to mitigate CVE-2026-27903
Fusion Content-Aware Storage - update to 1.1.5
IBM Fusion HCI - update to 2.13.0
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.4
Confluence Data Center - addressed in versions 9.2.21, 10.2.10
Jira Software Data Center - addressed in versions 10.3.22, 11.3.4
IBM QRadar Data Synchronization App - update to 4.0.0
External References
Related Security Bulletins
- Multiple vulnerabilities in minimatch
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Fusion, IBM Fusion HCI, and IBM Fusion Content-Aware Storage