CVE-2026-33671 is a Regular Expression Denial of Service (ReDoS) vulnerability impacting Picomatch, a JavaScript glob matcher, in versions prior to 4.0.4, 3.0.2, and 2.3.2. Rated 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), it allows an unauthenticated attacker to remotely cause a denial of service. This occurs when applications pass untrusted, crafted extglob patterns to Picomatch, leading to catastrophic backtracking, excessive CPU consumption, and blocking the Node.js event loop. There is currently no evidence of active exploitation or public exploit code, though the vulnerability has been noted in community discussions. Affected users should upgrade to a patched version or implement mitigations such as disabling extglob support for untrusted patterns.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.2CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.0.2CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.0.4CPE matchmatch criteria | cpe:2.3:a:jonschlinkert:picomatch:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.