Skip to content

Vulnerability in dependencies "minimatch" <10.2.1 #2267

Description

@danwater

minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - GHSA-3ppc-4f35-3m26

It appears that this application depends on "minimatch" 3.1.2 which is now listed as having a known vulnerability. I did try overriding the package to the fixed version but the API has changed and breaks functionality.

See above for the advisory and CVE: CVE-2026-26996

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions