npm vulnerability intelligence

minimatch NPM Package
Vulnerability Check

a glob matcher in javascript

High severity BlueOak-1.0.0 v10.2.5
Vulnerability Analysis OSV Live

minimatch

v10.2.5 · BlueOak-1.0.0 · 617,142,334 dl/wk

Advisory Breakdown

Critical 0
High 5
Moderate 0
Low 0

Severity Rating

High severity

5 advisories

High severity

Weekly downloads

617,142,334

Total advisories

5

Latest version

10.2.5

License

BlueOak-1.0.0

Known advisories

OSV records for the npm ecosystem

5
GHSA-23c5-xmqv-rm74 CVE-2026-27904 high

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Affected: >=10.0.0 <10.2.3, >=9.0.0 <9.0.7, >=8.0.0 <8.0.6, >=7.0.0 <7.4.8, >=6.0.0 <6.2.2, >=5.0.0 <5.1.8, >=4.0.0 <4.2.5, >=0 <3.1.4 Fixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 Updated Feb 28, 2026
View source
GHSA-3ppc-4f35-3m26 CVE-2026-26996 high

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

Affected: >=10.0.0 <10.2.1, >=9.0.0 <9.0.6, >=8.0.0 <8.0.5, >=7.0.0 <7.4.7, >=6.0.0 <6.2.1, >=5.0.0 <5.1.7, >=4.0.0 <4.2.4, >=0 <3.1.3 Fixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 Updated Feb 24, 2026
View source
GHSA-7r86-cg39-jmmj CVE-2026-27903 high

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Affected: >=10.0.0 <10.2.3, >=9.0.0 <9.0.7, >=8.0.0 <8.0.6, >=7.0.0 <7.4.8, >=6.0.0 <6.2.2, >=5.0.0 <5.1.8, >=4.0.0 <4.2.5, >=0 <3.1.3 Fixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 Updated Feb 28, 2026
View source
GHSA-f8q6-p94x-37v3 CVE-2022-3517 high

minimatch ReDoS vulnerability

Affected: >=0 <3.0.5 Fixed in: 3.0.5 Updated Feb 14, 2024
View source
GHSA-hxm2-r34f-qmc5 CVE-2016-10540 high

Regular Expression Denial of Service in minimatch

Affected: >=0 <3.0.2 Fixed in: 3.0.2 Updated Nov 8, 2023
View source

Checked May 22, 2026, 7:03 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
minimatch
Ecosystem
npm
Latest version
10.2.5
License
BlueOak-1.0.0
Weekly downloads
617,142,334

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 5/22/2026, 7:03:47 PM