Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-27904
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Source: NVD (National Vulnerability Database)
Vulnerability Description
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1333
Source: NVD (National Vulnerability Database)
Vulnerability Title
minimatch 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
minimatch是isaacs个人开发者的一个 javascript 中的全局匹配器。 minimatch 10.2.3之前版本、9.0.7之前版本、8.0.6之前版本、7.4.8之前版本、6.2.2之前版本、5.1.8之前版本、4.2.5之前版本和3.1.4之前版本存在安全漏洞,该漏洞源于嵌套*()扩展通配符产生具有嵌套无界量词的正则表达式,可能导致灾难性回溯。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
isaacsminimatch >= 10.0.0, < 10.2.3 -
II. Public POCs for CVE-2026-27904
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
kimi-k2.5 · 6887 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month
III. Intelligence Information for CVE-2026-27904
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-27904

No comments yet


Leave a comment