Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26996

30
FAUCET Score

CVE-2026-26996 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting minimatch versions 10.2.0 and below. This flaw allows an attacker to craft a malicious glob pattern with many consecutive wildcard characters, causing the application to consume excessive CPU resources and become unresponsive. The vulnerability has a CVSS score of 7.5 (High), indicating that it can be exploited remotely with low attack complexity, leading to a complete denial of service. There is currently no evidence of active exploitation, nor are there publicly available exploit tools like Metasploit or Nuclei modules. The vulnerability has received minimal community discussion and no media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.1.3CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
>= 4.0.0, < 4.2.4CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
>= 5.0.0, < 5.1.7CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.2.1CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
>= 7.0.0, < 7.4.7CPE matchmatch criteria
cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
41.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 19th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (116)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: minimatchFixed in: 10.2.1
npmpatch availablevia ghsa
Product: minimatchFixed in: 9.0.6
npmpatch availablevia ghsa
Product: minimatchFixed in: 8.0.5
npmpatch availablevia ghsa
Product: minimatchFixed in: 7.4.7
npmpatch availablevia ghsa
Product: minimatchFixed in: 6.2.1
npmpatch availablevia ghsa
Product: minimatchFixed in: 5.1.7
npmpatch availablevia ghsa
Product: minimatchFixed in: 3.1.3
npmpatch availablevia ghsa
Product: minimatchFixed in: 4.2.4
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp22/system
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp24/system
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp25/system
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp26/system
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel7
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel8
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/volsync-operator-bundle
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/volsync-rhel9
redhatno patchvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: org.jolokia-jolokia-parent
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-eda-controller
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-gateway
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-platform-ui
redhatno patchvia redhat_api
Product: Red Hat build of Apache Camel - HawtIO 4Fixed in: io.hawt-project
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: io.apicurio-apicurio-registry
redhatno patchvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: org.optaweb.vehiclerouting-optaweb-vehicle-routing
redhatno patchvia redhat_api
Product: Red Hat Data Grid 8Fixed in: org.infinispan-infinispan-console
redhatno patchvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/rhdh-hub-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: nodejs22
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: nodejs24
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:20/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:20/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:22/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:22/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:24/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nodejs:24/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: uglify-js
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:20/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:20/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:22/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:22/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:24/nodejs
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nodejs:24/nodejs-nodemon
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: polkit
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.apicurio-apicurito
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-hawtio-online
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-project
redhatno patchvia redhat_api
Product: Red Hat Fuse 7Fixed in: io.syndesis-syndesis-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: io.hawt-project
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: org.jboss.hal-hal-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: io.hawt-project
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.jboss.hal-hal-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: io.hawt-project
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.jboss.hal-hal-parent
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-data-science-pipelines-argo-argoexec-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-kf-notebook-controller-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-notebook-controller-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-agent-installer-ui-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-monitoring-plugin-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-monitoring-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/ocs-client-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/machineexec-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/openvsx-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/tempo-jaeger-query-rhel8
redhatno patchvia redhat_api
Product: Red Hat Process Automation 7Fixed in: org.kie-process-migration-service
redhatno patchvia redhat_api
Product: Red Hat Process Automation 7Fixed in: org.kie.workbench-kie-wb-common
redhatno patchvia redhat_api
Product: Red Hat Process Automation 7Fixed in: org.uberfire-uberfire-parent
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-advisor-frontend-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/mcg-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-vulnerability-frontend-rhel9
redhatno patchvia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: org.keycloak-keycloak-parent
redhatno patchvia redhat_api
Product: Self-service automation portal 2Fixed in: ansible-automation-platform/automation-portal
redhatno patchvia redhat_api
Product: streams for Apache Kafka 2Fixed in: com.github.streamshub-console
redhatno patchvia redhat_api
Product: streams for Apache Kafka 3Fixed in: com.github.streamshub-console
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/iop-host-inventory-frontend-rhel9
redhatno patchvia redhat_api
Product: Cryostat 4Fixed in: io.cryostat-cryostat
redhatno patchvia redhat_api
Product: Migration Toolkit for Applications 8Fixed in: mta/mta-ui-rhel9
redhatno patchvia redhat_api
Product: Node HealthCheck OperatorFixed in: workload-availability/node-remediation-console-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-api-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-db-migration-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp20/system
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp21/system
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/logging-view-plugin-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/kibana6-rhel8

Vendor Advisories (2)

redhatCVE-2026-26996Important

minimatch: minimatch: Denial of Service via specially crafted glob patterns

Feb 20, 2026
npmGHSA-3ppc-4f35-3m26high

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Feb 18, 2026

References

github.com / isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5
Patch
github.com / isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26
ExploitVendor Advisory