CVE-2026-27904

Aliases:GHSA-23c5-xmqv-rm74DEBIAN-CVE-2026-27904openSUSE-SU-2026:11446-1openSUSE-SU-2026:11447-1CGA-2gw3-7xrm-gx6pCGA-2px7-m75f-rjmxCGA-2w88-j53q-8g97CGA-34c9-8jc6-g24pCGA-37q7-746g-fxrfCGA-39m9-vq3x-wv3cCGA-39wp-qhvq-3qfxCGA-3f86-52jp-x499CGA-3j9w-vhr4-vf7vCGA-3q8r-x2wm-w9h9CGA-3rcp-cxf9-94fpCGA-3rw6-46ff-xm76CGA-3rx2-xmq8-wr8wCGA-3w63-4qj6-vgp5CGA-47mp-4m82-ggrfCGA-4c64-2f4x-3c3hCGA-4cg4-r244-wg76CGA-4fc7-9jx6-8qr2CGA-4pv3-4v42-7pw4CGA-4wh4-59c3-945pCGA-53v4-p3hv-7jc3CGA-5627-j463-f4rhCGA-5628-g4wg-pg44CGA-5c49-25qc-79xwCGA-5cww-h995-p6gpCGA-5fg8-g3vc-fq32CGA-5hfh-rffx-wmxmCGA-5q72-c632-2w6fCGA-5w6c-862h-xc7hCGA-6866-8hhf-qgm8CGA-6hhp-rh3m-28wcCGA-6vf5-rv8f-vjpcCGA-6xjg-4f8q-q6h6CGA-72rp-2p2j-v753CGA-76xf-pghv-cw86CGA-7g8x-6mj6-5qr2CGA-7q57-35ff-hgc8CGA-7qqv-x4x3-3qgvCGA-7qvg-rpxq-976qCGA-7w34-4832-j66vCGA-8hvq-hmrc-r6jmCGA-8r8v-q5q4-mmhhCGA-8wmf-vg4p-mpr3CGA-933g-9rm8-ppfxCGA-99xq-mp39-v2qrCGA-9g7q-vhqm-h58hCGA-9h6x-46fp-68w6CGA-9p77-2j68-w3xgCGA-9r2g-qvmc-p9r9CGA-c34f-gh26-cpf2CGA-c38f-775h-597cCGA-c4gc-fqp8-84g3CGA-c99w-6p2m-8vh4CGA-ccq5-x7vx-9vj5CGA-cwjf-mq6v-4xmxCGA-f8r3-6g82-frr8CGA-fc4g-gc7v-wg3wCGA-fcgx-8fgv-m8hxCGA-fg3r-xj44-9gmjCGA-fh78-rf2g-7964CGA-fqrv-9856-fq38CGA-g3ch-6g88-99j6CGA-g56h-2gpm-883xCGA-gj7j-m3xm-f9qrCGA-gxhx-m3pv-m3x8CGA-h84c-m554-xjccCGA-hcv9-m8h9-cx4pCGA-hhf5-c8c7-m6mhCGA-hhv3-5v48-v8q5CGA-hhv6-f8q8-x9wmCGA-hj4p-896p-rxvcCGA-hp8r-3vr6-78v6CGA-hr77-5cpm-xhj4CGA-hwr3-7wm3-r7jqCGA-hxgw-h9mw-gh2gCGA-j2m3-g8j8-2jhxCGA-j35x-3xh3-j278CGA-j46g-4fmp-q2g6CGA-jg5w-vjm7-gcx9CGA-jg6f-gmx9-m5rjCGA-jrx2-732m-hjp4CGA-jwvj-3jfj-334cCGA-m3p6-765c-48p8CGA-m6v5-4qpg-hq2xCGA-m72x-hgcc-26q5CGA-m7w5-r4ww-mmgrCGA-mhmq-pqx6-f563CGA-mj25-r9ff-5469CGA-mwmg-xqrh-q2jcCGA-p588-vwrm-qfcrCGA-pc5f-9v5v-gh67CGA-phr8-vf9m-gmj4CGA-pjcq-6f2q-fq6jCGA-pmrm-29j6-rj8rCGA-pmxq-fg44-xvrmCGA-237h-qgvh-4p6rCGA-25qm-82jx-2hv3CGA-288w-xx64-rrc5CGA-28rx-phpf-4xr5CGA-29qm-m59x-q264CGA-2c3p-c6xw-ghv7CGA-2c6q-jq7x-87phCGA-2cxp-79v8-rm57CGA-2ffr-grfr-wwx2CGA-2hf8-8jjg-mf7qCGA-2hfg-j9px-7969CGA-2hfh-cg99-qfx4CGA-2mcf-mqxv-r6w8CGA-2prx-3cx3-9fpwCGA-2q9h-7mc3-6rrcCGA-2qqc-rm6w-wxc4CGA-2w58-2gmj-4q6vCGA-2wq6-52f9-w3q7CGA-2x84-77x9-mr5qCGA-35mg-jqp3-2558CGA-35r4-xh7v-qc67CGA-35vm-vpxg-88x6CGA-37g3-68m4-x3jgCGA-38fh-32v6-cr23CGA-3c3m-w27g-f42xCGA-3jfr-7q8f-p5g6CGA-3m66-cf5p-qr2wCGA-3m7v-v3c4-rhx7CGA-3mxf-8grc-wm9xCGA-3qfm-95jv-6w8hCGA-3qmw-3p4q-wcp4CGA-3wph-9v35-6x9wCGA-3wqc-grhh-f329CGA-4784-h7qx-46j5CGA-49fx-mx46-52c6CGA-4f26-gmpx-q96xCGA-4f8w-6m38-87rxCGA-4gqf-phmj-4q9vCGA-4j3q-5c9v-jmggCGA-4j8m-xh5g-269hCGA-4p2m-39fw-5m52CGA-4p68-633r-5f49CGA-4qpv-mmhj-64mcCGA-4qw8-hw4c-rpvxCGA-4wjf-xh37-6pppCGA-4xc5-9v7g-9r62CGA-4xjp-rf3f-7v9wCGA-52pq-fr8c-vcw8CGA-52rm-vh99-xhgrCGA-5555-6m2c-x45wCGA-57c8-p3wv-2q3gCGA-594v-53jm-7jw6CGA-5cqh-jww7-f62mCGA-5h5g-j9hm-8hqwCGA-5h87-3m7g-9hcxCGA-5q5v-jp47-fwh3CGA-5vr7-523h-wm35CGA-624q-jpr4-6653CGA-66vp-3rq9-q352CGA-675c-ghc8-8hg7CGA-68f2-4f87-p67rCGA-68vg-rq2j-jpcmCGA-6c62-6gx6-94mrCGA-6cwv-96f8-cmmmCGA-6f48-7mqh-qq9vCGA-6hc8-3w6j-vjq4CGA-6jr7-5mw8-2vq2CGA-6q38-qpc6-h46cCGA-6v9f-jrw7-gp74CGA-6w84-hmxg-vrwgCGA-75v9-f2xg-6jhvCGA-77jp-w7rg-5mvqCGA-77v2-r3vh-m5c8CGA-7fcw-6m53-c5jvCGA-7mhj-qf3q-x25gCGA-82cp-7vph-gmccCGA-83v4-62hp-gjjwCGA-852w-fxqp-xxhmCGA-87xp-xpqm-5mf4CGA-8c8g-c6fw-jv5rCGA-8cff-3229-48grCGA-8f74-c894-wc6rCGA-8pcp-cr3x-hppfCGA-8pgg-rvqq-4c3cCGA-8q74-v59q-57v2CGA-8qv6-6mvj-2m77CGA-8w57-344r-3w8fCGA-8wv6-hgv7-3fqmCGA-8x9f-x92g-wh2wCGA-8xrp-h8cg-58m7CGA-9343-7hmh-rj89CGA-934g-jxxm-m6qcCGA-94xm-rwgp-mgwqCGA-95xm-pjg4-hqggCGA-9685-g6qp-p93jCGA-98gh-hh5x-24m8CGA-9c33-hjf5-f59gCGA-9h7w-r32w-j3cgCGA-9jjf-vqgq-r368CGA-9jqq-pwg6-f4q4CGA-9p88-g8m6-3p2hCGA-9pj9-5r2c-cfw4CGA-9pw6-qp2x-2pgxCGA-9qph-gfx2-chw4CGA-9rh9-j4hw-h3rxCGA-9rqw-47x6-9g2vCGA-9v4f-rp74-2r4gCGA-9vgr-5389-m65qCGA-9vh9-9jq3-f7w3CGA-9wg2-fhmx-934rCGA-c2rj-m8q7-fmf9CGA-c2rx-mqhq-8r7hCGA-c47h-w4c6-mfx5CGA-c5mj-h448-jwrfCGA-c5q8-2ww2-9539CGA-c6fp-m7gm-5q7hCGA-c7q2-93xv-5gq6CGA-c7r2-whh9-23grCGA-c8q5-8gww-9ff5CGA-cfxm-c52x-vvg3CGA-cg4f-rcgc-x8mmCGA-cg95-2766-gpvpCGA-cmf3-cgmq-f3qxCGA-crp8-7f4p-vpw5CGA-cvp4-xc3q-7g4fCGA-cw7q-jfh6-2878CGA-cwvw-xjhh-vq8hCGA-f3vr-wr63-4xw5CGA-f794-jcgw-pwwmCGA-f9f9-j32q-mg88CGA-fhc4-g6pp-m484CGA-fpx4-7wp2-wrqgCGA-fx63-wghv-qx5jCGA-g32c-cv4m-3v4xCGA-g8r4-grrc-h3hjCGA-gc4v-vhjj-w8rhCGA-gff5-2hfc-49r4CGA-ggpf-wj53-6jg3CGA-ggq8-rm6p-wmxrCGA-gjhg-6hpc-hj69CGA-gmmf-9xpr-fcgfCGA-gp3g-h2rh-fw33CGA-gpg7-c2f4-3hx8CGA-gqgc-x53x-8xf4CGA-gqrv-gjw3-62r5CGA-grwf-4hp9-6cqmCGA-gv79-8732-xrhmCGA-h36f-vv6g-4x3hCGA-h774-3wc3-w73fCGA-h8vr-mr7g-r6m7CGA-h972-mm2p-gv38CGA-hcf9-85cq-8x2vCGA-hcj3-gmj9-vwp2CGA-hf54-hg5m-h2fxCGA-hfgp-7xf8-hgp6CGA-hgvv-x49h-ghwmCGA-hhfx-j4rp-g7gxCGA-hj5x-w3vg-w596CGA-hjv9-78hv-xg72CGA-hmc3-45wj-2phfCGA-hp37-h27g-fvmjCGA-hq25-8686-vcjfCGA-hq8w-m954-pf74CGA-hr9q-ch4r-r986CGA-hvvm-wpp6-gcwhCGA-hx95-3prh-792jCGA-hxpx-mjg8-rx7fCGA-hxw3-7v9w-97rjCGA-j4pw-j9cr-5wprCGA-j6qw-3pmh-9pjvCGA-j99r-85gm-xm83CGA-j9pp-h7gf-368hCGA-j9r4-5q8v-hh8pCGA-jfhq-j325-55rjCGA-jfjm-xpj6-x2gjCGA-jg6m-3wpj-3f8pCGA-jh76-52wv-v29gCGA-jp4g-rgcg-465vCGA-jpj2-89f3-hvf8CGA-jv9r-c9x9-hjwjCGA-jvfg-5g9h-r9c9CGA-jvxp-h5rw-r5xhCGA-jw7q-m2xw-3c5jCGA-m42c-8jvf-7v5fCGA-m47g-jqj2-ggppCGA-m9jr-57gw-m99gCGA-mf29-gg5v-xwwhCGA-mfp3-7fx6-7fh8CGA-mgfr-5qpq-rh7gCGA-mgqr-3j28-xxjjCGA-mh58-3h25-3v9pCGA-mh7x-4qcg-xfqcCGA-mp6x-xgxp-rf66CGA-mrh8-6v5m-hmvmCGA-mvg6-m7c2-756qCGA-mw95-cv7m-2rrpCGA-p3x4-p68m-fqhxCGA-p3x9-89x3-3grrCGA-p436-rfqx-fg7gCGA-p48g-4xr3-xcgjCGA-p5rf-qx36-6858CGA-p6wf-gj26-9vqpCGA-p7x9-2745-4jrqCGA-p8pf-75x6-7v9rCGA-pc26-7qwv-jqw5CGA-pcm8-5jfc-wwfpCGA-pg4g-jph2-fv24CGA-pg6f-p7c2-qhppCGA-pg7m-fwgw-837jCGA-pjrj-7vqf-55qmCGA-pmjj-pfjc-8cvcCGA-pq4r-wq9h-mxhrCGA-pw86-628p-vjfcCGA-q2q9-mh7c-h59hCGA-q34j-wfp7-9x4jCGA-q4f6-crrg-9vg7CGA-q4x6-65vw-9w3fCGA-q59g-fv5p-62xrCGA-q67v-74r3-2v93CGA-q77g-9548-cxxrCGA-q7cm-m3pm-9m37CGA-q84w-44rg-x8x2CGA-q8fc-7f29-5rf6CGA-q95f-882w-5596CGA-qf39-p52m-c256CGA-qf4v-37j3-3fjxCGA-qg5v-4p96-p862CGA-qh7g-f724-37whCGA-qjcv-49pm-5gfqCGA-qm2f-4rrp-rhpjCGA-qm4j-rmqw-49rwCGA-qqm4-cwhg-whwqCGA-qqmc-rcrj-jqhvCGA-qvfr-4839-h5q7CGA-qvgq-c55p-g26cCGA-qwq3-rjpw-m4wgCGA-r2qg-h49v-gvc5CGA-r367-p9m7-m8w7CGA-r38m-j2ww-3xwwCGA-r38p-chw8-6mjqCGA-r665-m87c-jhrpCGA-r67x-m552-fxqcCGA-r6x4-2mph-w9vfCGA-r8ph-g96c-9jqhCGA-r978-3g36-h8c3CGA-r9cx-4gx7-2xhcCGA-rc98-8r4c-hr92CGA-rch5-462v-r95hCGA-rf2v-f9w4-c8vvCGA-rf6f-2c9m-r98wCGA-rfw2-mph7-vv79CGA-rg6r-q38m-gcvpCGA-rg9q-2pm9-mxxpCGA-rhh5-2pgj-28xhCGA-rm4r-mg3q-5j5qCGA-rqp6-fj37-v65cCGA-rrjr-98vr-2v69CGA-rrwv-rww7-2ccxCGA-rrx8-g246-373gCGA-v3f2-p2jj-6966CGA-v4fh-g732-v928CGA-v4j4-3xjm-2329CGA-v549-3rgf-mgm4CGA-v5gq-3w42-7qhpCGA-v75x-vq53-p77vCGA-v76v-2242-2h66CGA-v795-cwh6-p86vCGA-v797-gv87-9q84CGA-v8cr-wx4m-9jc8CGA-v8vx-v737-hc28CGA-vhrp-2rj4-hjmpCGA-vhwr-6mpp-9jw8CGA-vjg7-9gjf-2r32CGA-vm25-hhgp-fjhgCGA-vm8w-8qhq-qh82CGA-vp6g-f8qm-2gvhCGA-vph5-hvhx-9w4cCGA-vpmr-v4gf-h5rfCGA-vrm6-fc8f-6r9mCGA-vv4j-vq63-h4h3CGA-vx2g-87qx-5h93CGA-vxvx-6rjf-mrfvCGA-w32g-w3fv-ppggCGA-w473-cx4q-qm98CGA-w4rr-pq8v-2c8fCGA-w5jr-2g8v-gwfhCGA-w5rx-333w-qf83CGA-w6vq-g44h-hf7mCGA-w76p-h52h-9m63CGA-w86q-qj3p-6rwpCGA-w927-r3mm-p6p8CGA-w92g-h96r-vhx2CGA-wfrv-hc72-6hhgCGA-wp3g-h7fx-2676CGA-wp5w-6qxc-fhv4CGA-wqqv-r4r4-qmj9CGA-wv23-9w6r-fjmqCGA-wvfg-q4jr-49rrCGA-wvx6-ppwx-ppm4CGA-ww7r-jjc9-g7m6CGA-wwx2-q485-h38mCGA-wx65-mr46-73q4CGA-wxfv-x8h7-q72wCGA-x6p9-cvr2-772fCGA-x94v-h4j7-hjr2CGA-x952-8jx5-xvg8CGA-xcc5-fcrp-pq87CGA-xg5q-rxgp-44rmCGA-xh4q-76m7-fqxqCGA-xj9p-4464-57hxCGA-xjxv-r94m-q624CGA-xm88-frjq-x32cCGA-xm9j-8f6f-v68gCGA-xp5g-c23m-jhqxCGA-xpwc-qphh-9mmgCGA-xpwf-c4mp-m942CGA-xq86-75x8-p9x6CGA-xqm8-v3c3-6ww5CGA-xrww-6mv8-pc4qCGA-xv38-2652-3pvwCGA-xv6r-fw64-gvh8CGA-xx75-77mm-62vjCGA-239p-fjw7-2594CGA-qhmq-c7m2-49p2
Analyzed
Published: 26 Feb 2026, 01:07
Last modified:26 Feb 2026, 19:21

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.47% LOW
0% probability +0.45%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 Feb 2026, 01:07
Published
Vulnerability first disclosed
26 Feb 2026, 19:21
Last Modified
Vulnerability information updated

Description

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default `minimatch()` API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects `+()` extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • chainguardactions-runner

    < 2.332.0-r1

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.3-r2

  • chainguardarangodb-3.12

    < 3.12.7.2-r3

  • chainguardargo-workflows-ui-3.6

    < 3.6.19-r6

  • chainguardargo-workflows-ui-3.7

    < 3.7.13-r2

  • chainguardargo-workflows-ui-4.0

    < 4.0.4-r6

  • chainguardauthentik-2025.12

    all

  • chainguardauthentik-2026.2

    < 2026.2.4-r9

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.2

    < 2026.2.4-r8

  • chainguardbash-language-server

    < 5.6.0-r4

  • chainguardcode-server

    < 4.109.2-r0

  • chainguarddrupal-11.3

    < 11.3.13-r1

  • chainguardemscripten

    < 5.0.2-r1

  • chainguardeslint

    < 10.0.2-r1

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    < 18.11.6-r7

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all | < 19.0.3-r1

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    < 18.1.6-r15 | all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.7-r1

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.1-r1 | all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardgraalvm-24-ce-nodejs

    all

  • chainguardgraalvm-25-ce-nodejs

    < 25.0.2-r4

  • chainguardjupyter-base-notebook

    all

  • chainguardkatib-earlystopping

    < 0.19.0-r23

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r23

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r23 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r23

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r23

Showing first 50 affected entries in server-rendered view.

References (7)