minimatch

a glob matcher in javascript

npm latest 10.2.6 BlueOak-1.0.0

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

10.2.6

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

5 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

5

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Affected range

SEMVER: introduced 10.0.0; fixed 10.2.3SEMVER: introduced 9.0.0; fixed 9.0.7SEMVER: introduced 8.0.0; fixed 8.0.6SEMVER: introduced 7.0.0; fixed 7.4.8SEMVER: introduced 6.0.0; fixed 6.2.2

Fixed versions: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Affected range

SEMVER: introduced 10.0.0; fixed 10.2.3SEMVER: introduced 9.0.0; fixed 9.0.7SEMVER: introduced 8.0.0; fixed 8.0.6SEMVER: introduced 7.0.0; fixed 7.4.8SEMVER: introduced 6.0.0; fixed 6.2.2

Fixed versions: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Affected range

SEMVER: introduced 10.0.0; fixed 10.2.1SEMVER: introduced 9.0.0; fixed 9.0.6SEMVER: introduced 8.0.0; fixed 8.0.5SEMVER: introduced 7.0.0; fixed 7.4.7SEMVER: introduced 6.0.0; fixed 6.2.1

Fixed versions: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3