CVE Explorer
CVE-2026-33671
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"picomatch","vendor":"micromatch","versions":[{"status":"affected","version":">= 4.0.0, < 4.0.4"},{"status":"affected","version":">= 3.0.0, < 3.0.2"},{"status":"affected","version":"< 2.3.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:205d5f0e02a32a938e56208a439300bb75c90425315719b92410e48146138e5b · sha256:fc8026984dc0ec20… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:205d5f0e02a32a938e56208a439300bb75c90425315719b92410e48146138e5b · sha256:fc8026984dc0ec20… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1333","description":"CWE-1333: Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:205d5f0e02a32a938e56208a439300bb75c90425315719b92410e48146138e5b · sha256:fc8026984dc0ec20… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/micromatch/picomatch/commit/5eceecd27543b8e056b9307d69e105ea03618a7d","tags":["x_refsource_MISC"],"url":"https://github.com/micromatch/picomatch/commit/5eceecd27543b8e056b9307d69e105ea03618a7d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:205d5f0e02a32a938e56208a439300bb75c90425315719b92410e48146138e5b · sha256:fc8026984dc0ec20… · /containers/cna/references/1
{"name":"https://github.com/micromatch/picomatch/security/advisories/GHSA-c2c7-rcm5-vvqj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/micromatch/picomatch/security/advisories/GHSA-c2c7-rcm5-vvqj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:205d5f0e02a32a938e56208a439300bb75c90425315719b92410e48146138e5b · sha256:fc8026984dc0ec20… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.