Junglewise Threat Intelligence

CVE-2026-27904: minimatch nested extglob ReDoS via catastrophic backtracking

CVE-2026-27904 · Severity: low · CVSS 3.1 · Published 2026-02-26

Technologies: Isaacs Minimatch.

Executive brief

minimatch is a JavaScript glob pattern matching library used by npm and build tools. Nested extended glob patterns like `*(*(a|b))` generate regular expressions with nested quantifiers that cause the regex engine to hang for seconds or minutes when processing non-matching input. An attacker who can control glob patterns in build pipelines or file path matching operations can trigger denial-of-service by stalling the event loop.

Technical details

This is a Regular Expression Denial of Service (ReDoS) vulnerability in the glob pattern compiler. The root cause is in AST.toRegExpSource() at src/ast.ts#L598, where nested extglobs (e.g., `*()` and `+()` operators) produce unbounded quantifiers that wrap recursively: `*(a|b)` becomes `/^(?:a|b)*$/`, but `*(*(a|b))` becomes `/^(?:(?:a|b)*)*$/`. These nested quantifiers exhibit catastrophic backtracking in V8 when matching against adversarial non-matching input (e.g., repeated 'a' characters followed by 'z'). A 12-byte pattern with 18-byte input can stall for 7+ seconds; additional nesting levels or input length push execution time to minutes. The vulnerability is triggered through the default minimatch() API without special options. Patches have been released in versions 3.1.4, 4.2.5, 5.1.8, 6.2.2, 7.4.8, 8.0.6, 9.0.7, and 10.2.3.

Affected products

  • isaacs minimatch >=0.0.0, <=3.1.3; >=4.0.0, <4.2.5; >=5.0.0, <5.1.8; >=6.0.0, <6.2.2; >=7.0.0, <7.4.8; >=8.0.0, <8.0.6; >=9.0.0, <9.0.7; >=10.0.0, <10.2.3

Timeline

  • 2026-02-25: disclosed: Vulnerability published on GitHub advisories
  • 2026-02-25: patched: Patched versions released: 3.1.4, 4.2.5, 5.1.8, 6.2.2, 7.4.8, 8.0.6, 9.0.7, 10.2.3

References