Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-3517

26
FAUCET Score

CVE-2022-3517 is a Regular Expression Denial of Service (ReDoS) vulnerability in the minimatch package, affecting various Debian and Fedora distributions. This flaw allows an unauthenticated attacker to trigger a Denial of Service by providing specific arguments to the braceExpand function. With a CVSS score of 7.5 (High), it presents a low-complexity network-based attack that can lead to system unavailability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.0.5CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.67%
Probability of exploitation in next 30 days
EPSS Percentile
74.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0167 is in the 57th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (59)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: minimatchFixed in: 3.0.5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:16-8070020221207164159.bd1311ed
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:14-8070020221212161539.bd1311ed
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:14-8070020230306170042.bd1311ed
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: nodejs:14-8040020230306170312.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: nodejs:14-8060020230306170237.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs-1:16.18.1-3.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs-nodemon-0:2.0.20-2.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-nodejs-0:14.21.1-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nodejs14-nodejs-nodemon-0:2.0.20-2.el7
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.13-RHEL-9Fixed in: odf4/mcg-core-rhel9:v4.13.0-41
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Data Foundation 4.19Fixed in: odf4/odf-cloudnative-pg-rhel9-operator:sha256:ac20578ab27c892b5243473cf3e5f80c3aecdf1958b43869cd2c8ec6b61062a0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.24Fixed in: devspaces/code-rhel9:sha256:e8cb98ec2e7a8ad2ccd69796bc78b812df25bcb8be60808f1b66b56cc0e2fd99
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:18-9010020221118120946.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Runtimes 1 on RHEL 8Fixed in: nodejs-minimatch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:18-8070020221118123310.bd1311ed
View patch
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Migration Toolkit for ContainersFixed in: rhmtc/openshift-migration-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-prometheus
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-api-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-docs-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-rhel8-operator
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: aap-azure-ui
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: nodejs-minimatch
redhatno patchvia redhat_api
Product: Red Hat Discovery 1Fixed in: discovery-server-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-rhel8-container
redhatend of lifevia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-all-in-one-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-query-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: odo
redhatend of lifevia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: cockpit-ceph-installer
redhatend of lifevia redhat_api
Product: Red Hat Directory Server 11Fixed in: redhat-ds:11/389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Directory Server 12Fixed in: redhat-ds:12/389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite:el8/rubygem-rabl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: 389-ds:1.4/389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: 389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gjs
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: nodejs-minimatch
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-grafana
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-system-container
redhatend of lifevia redhat_api
Product: Red Hat Satellite 6Fixed in: tfm-rubygem-rabl
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-api-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-endpoint-rhel8-container
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-ui-rhel8

Vendor Advisories (3)

bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
npmGHSA-f8q6-p94x-37v3high

minimatch ReDoS vulnerability

Oct 18, 2022
redhatCVE-2022-3517Moderate

nodejs-minimatch: ReDoS via the braceExpand function

Feb 6, 2022

References

github.com / grafana/grafana-image-renderer/issues/329
Issue TrackingPatchThird Party Advisory
github.com / isaacs/minimatch/commit/a8763f4388e51956be62dc6025cec1126beeb5e6
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2023/01/msg00011.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK