Executive brief
minimatch is a widely-used JavaScript library for wildcard pattern matching in file paths. A Regular Expression Denial of Service (ReDoS) flaw allows attackers to cause service outages by passing specially crafted input to the braceExpand function, which can consume CPU resources and hang applications that depend on the library.
Technical details
A ReDoS vulnerability exists in the minimatch library due to an unoptimized regex pattern (/\{.*\}/) used in the braceExpand function. An attacker can provide specific malformed input that causes catastrophic backtracking in the regex engine, leading to excessive CPU consumption and denial of service. The vulnerability is triggered when braceExpand is called with adversarial input; no authentication or user interaction is required if the vulnerable function is exposed through a network-facing application. An attacker can exploit this to crash or hang services that process untrusted glob patterns. The vulnerability has been fixed in minimatch version 3.0.5 and later.
Affected products
- isaacs minimatch before 3.0.5
Timeline
- 2022-10-17: disclosed: Published on NVD
- 2022-10: patched: Fixed in version 3.0.5