Inefficient Algorithmic Complexity in minimatch - CVE-2026-27903
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in matchOne() when processing glob patterns containing multiple non-adjacent GLOBSTAR segments. A remote attacker can supply a specially crafted glob pattern to cause a denial of service.
The issue is triggered on non-matching input and can stall the Node.js event loop while the recursive call tree is fully explored.
Affected software
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
How to mitigate CVE-2026-27903
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.4
Confluence Data Center - addressed in versions 9.2.21, 10.2.10
Jira Software Data Center - addressed in versions 10.3.22, 11.3.4