CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

  • Published Oct 17, 2022
  • CVSS 7.5 high
  • 1.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2022-3517 at the National Vulnerability Database