m
minimatch project
Security Risk Profile
32
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 31, 2018 to present
5
Total CVEs
5
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
32/100
low
Severity Distribution
Critical
0High
5Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
3Age Distribution
Common Weaknesses (CWE)
1
Input Validation
1
Most Affected Products
1. npm/minimatch36
2. Minimatch Project Minimatch Node.js27
3. IBM Business Automation Insights6
4. IBM Concert Software3
5. redhat/nodejs2
Recent Vulnerabilities
See more →CVE-2026-27904
CVSS 7.5EPSS 0%high
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Feb 26, 2026
CVE-2026-27903
CVSS 7.5EPSS 0%high
minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
Feb 26, 2026
CVE-2026-26996
CVSS 8.7EPSS 0%high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
Feb 18, 2026
CVE-2022-3517
CVSS 7.5high
Feb 6, 2022
CVE-2016-10540
CVSS 7.5high
May 31, 2018
Monitor minimatch project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.