« Volver al listado

CVE-2026-27904

Estado: AnalizadaAlta (7.5)—

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes.

Leer descripción completaMostrar menos

This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Librería Node.js expuesta en red sin autenticación (AV:N, PR:N). Patrones glob maliciosos causan backtracking catastrófico, stalling de >7 segundos (DoS de aplicación).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-27904",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-27904",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-26T19:21:18.964387Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "isaacs",
          "product": "minimatch",
          "versions": [
            {
              "status": "affected",
              "version": ">= 10.0.0, < 10.2.3"
            },
            {
              "status": "affected",
              "version": ">= 9.0.0, < 9.0.7"
            },
            {
              "status": "affected",
              "version": ">= 8.0.0, < 8.0.6"
            },
            {
              "status": "affected",
              "version": ">= 7.0.0, < 7.4.8"
            },
            {
              "status": "affected",
              "version": ">= 6.0.0, < 6.2.2"
            },
            {
              "status": "affected",
              "version": ">= 5.0.0, < 5.1.8"
            },
            {
              "status": "affected",
              "version": ">= 4.0.0, < 4.2.5"
            },
            {
              "status": "affected",
              "version": "< 3.1.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-26T02:16:21.760",
  "references": [
    {
      "url": "https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1333"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue."
    },
    {
      "lang": "es",
      "value": "minimatch es una utilidad de coincidencia mínima para convertir expresiones glob en objetos RegExp de JavaScript. Antes de las versiones 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5 y 3.1.4, los extglobs anidados '*( )' producen regexps con cuantificadores anidados ilimitados (por ejemplo, '(?:(?:a|b)*)*'), que exhiben retroceso catastrófico en V8. Con un patrón de 12 bytes '*(*(*(a|b)))' y una entrada no coincidente de 18 bytes, 'minimatch()' se detiene durante más de 7 segundos. Añadir un solo nivel de anidamiento o unos pocos caracteres de entrada eleva esto a minutos. Este es el hallazgo más grave: se activa por la API predeterminada de 'minimatch()' sin opciones especiales, y el patrón mínimo viable es de solo 12 bytes. El mismo problema afecta a los extglobs '+()' por igual. Las versiones 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5 y 3.1.4 solucionan el problema."
    }
  ],
  "lastModified": "2026-06-17T10:27:51.297",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41106C86-4D1E-40C7-851F-2564462205C3",
              "versionEndExcluding": "3.1.4"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39C23B15-E8E5-4847-A6EF-0940FA9F26BF",
              "versionEndExcluding": "4.2.5",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA03D53D-D7C4-424A-A3BA-C8C3B90D3EA2",
              "versionEndExcluding": "5.1.8",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3677470-9515-47D2-B5FB-4FA1F700ED55",
              "versionEndExcluding": "6.2.2",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A34E360D-31EA-43CF-957E-5D2208076EBF",
              "versionEndExcluding": "7.4.8",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6391D830-3745-4C96-A6CF-A6C75CC221A5",
              "versionEndExcluding": "8.0.6",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E6BE4CC-B5A1-4FC8-8776-9BEA2B10F6D7",
              "versionEndExcluding": "9.0.7",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B5B4C6E-7FBB-4C95-BD32-B3A16C6B1E5B",
              "versionEndExcluding": "10.2.3",
              "versionStartIncluding": "10.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}