Minimatch Project maintains a focused pattern-matching library widely embedded in Node.js toolchains and build systems, despite a narrow product footprint. The durable vulnerability signal centers on the library's regex-based matching engine, with recurring issues rooted in inefficient regular-expression complexity, uncontrolled resource consumption, and improper input validation that can degrade performance or consume excessive memory under adversarial input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minimatch Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27904HIGH minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 | Feb 26, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-27903HIGH minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3 | Feb 26, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-26996HIGH minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Ser | Feb 20, 2026 | 7.5 | 30 | NO | NO |
CVE-2022-3517HIGH A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, r | Oct 17, 2022 | 7.5 | 26 | NO | NO |
CVE-2016-10540HIGH Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3. | May 31, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minimatch Project.
Media articles that mention a CVE ID that affects a product developed by Minimatch Project — matched by CVE ID, not by vendor name.