minimatch
isaacs- Product type
- Other
- Catalog vulnerabilities
- 3
Severity across 3 analyzed records
Verify to analyze this security profile
en
As of 09/15/2026, within CyStack's analyzed data, minimatch has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of minimatch and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-27904minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions | Exploitation statusPublic exploit | FixNot confirmed | Published02/26/2026 | SeverityHigh |
CVE-2026-27903minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments | Exploitation statusPublic exploit | FixNot confirmed | Published02/26/2026 | SeverityHigh |
CVE-2026-26996minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityHigh |