Skip to content

CVE-2026-26996 CVE-2026-27903 minimatch has a ReDoS via repeated wildards with non-matching literal in pattern, minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments - #997

Merged
maximthomas merged 1 commit into
OpenIdentityPlatform:masterfrom
maximthomas:issues/ui-minimax-update
Apr 15, 2026

Conversation

@maximthomas

Copy link
Copy Markdown
Contributor

No description provided.

…cards with non-matching literal in pattern, minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
@maximthomas
maximthomas merged commit c068ff2 into OpenIdentityPlatform:master Apr 15, 2026
0 of 15 checks passed
maximthomas added a commit to maximthomas/OpenAM that referenced this pull request Apr 15, 2026
* CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 UI: update grunt to 1.6.2 to address vulnerabilities

* CVE-2026-26996 CVE-2026-27903 minimatch has a ReDoS via repeated wildards with non-matching literal in pattern, minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments (OpenIdentityPlatform#997)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant