Skip to content

[GHSA-3ppc-4f35-3m26] minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern#7048

Closed
marcelstoer wants to merge 1 commit intomarcelstoer/advisory-improvement-7048from
marcelstoer-GHSA-3ppc-4f35-3m26
Closed

[GHSA-3ppc-4f35-3m26] minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern#7048
marcelstoer wants to merge 1 commit intomarcelstoer/advisory-improvement-7048from
marcelstoer-GHSA-3ppc-4f35-3m26

Conversation

@marcelstoer
Copy link

Updates

  • Affected products

Comments
GHSA-3ppc-4f35-3m26 listed the fixes in legacy versions of minimatch. AFAIU the two advisories are identical but "Affected versions" and "Patched versions" were inconsistent so far.

@github
Copy link
Collaborator

github commented Feb 24, 2026

Hi there @isaacs! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to marcelstoer/advisory-improvement-7048 February 24, 2026 09:36
@HolgerJeromin
Copy link

it is duplicate from #7002

@github-actions github-actions bot deleted the marcelstoer-GHSA-3ppc-4f35-3m26 branch February 24, 2026 11:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants