Unbounded Recursive Backtracking Vulnerability in Minimatch Utility by Isaac's
CVE-2026-27903

7.5HIGH

Key Information:

Vendor

Isaacs

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-27903?

The minimatch utility, essential for converting glob expressions into JavaScript regular expressions, exhibits unbounded recursive backtracking before version 10.2.3, among others. This flaw occurs when a glob pattern includes multiple non-adjacent GLOBSTAR (**) segments, leading to excessive delays in processing. Under certain conditions, an attacker can submit crafted patterns that stall the Node.js event loop for significant periods, impacting the performance of applications using this utility. This poses a risk in diverse environments, especially in build tools, CI/CD pipelines, and systems where user-supplied inputs dictate behavior.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

minimatch >= 10.0.0, < 10.2.3 < 10.0.0, 10.2.3

minimatch >= 9.0.0, < 9.0.7 < 9.0.0, 9.0.7

minimatch >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.