CVE-2026-27904
中文标题:
(暂无数据)
英文标题:
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
漏洞描述
中文描述:
(暂无数据)
英文描述:
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| isaacs | minimatch | >= 10.0.0, < 10.2.3 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_10.0.0,_<_10.2.3:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 9.0.0, < 9.0.7 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_9.0.0,_<_9.0.7:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 8.0.0, < 8.0.6 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_8.0.0,_<_8.0.6:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 7.0.0, < 7.4.8 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_7.0.0,_<_7.4.8:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 6.0.0, < 6.2.2 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_6.0.0,_<_6.2.2:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 5.0.0, < 5.1.8 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_5.0.0,_<_5.1.8:*:*:*:*:*:*:*
|
| isaacs | minimatch | >= 4.0.0, < 4.2.5 | - | - |
cpe:2.3:a:isaacs:minimatch:>=_4.0.0,_<_4.2.5:*:*:*:*:*:*:*
|
| isaacs | minimatch | < 3.1.4 | - | - |
cpe:2.3:a:isaacs:minimatch:<_3.1.4:*:*:*:*:*:*:*
|
| minimatch_project | minimatch | * | - | - |
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-27904 |
2026-02-26 03:19:54 | 2026-02-25 22:00:02 |
| NVD | nvd_CVE-2026-27904 |
2026-02-27 02:00:05 | 2026-02-26 22:00:03 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 8 -> 9
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']