[Git][security-tracker-team/security-tracker][master] Add two node-minimatch issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Feb 26 20:09:49 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0c55cfac by Salvatore Bonaccorso at 2026-02-26T21:09:24+01:00
Add two node-minimatch issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,9 +81,13 @@ CVE-2026-27938 (WPGraphQL provides a GraphQL API for WordPress sites. Prior to v
 CVE-2026-27933 (Manyfold is an open source, self-hosted web application for managing a ...)
 	NOT-FOR-US: Manyfold
 CVE-2026-27904 (minimatch is a minimal matching utility for converting glob expression ...)
-	TODO: check
+	- node-minimatch <unfixed>
+	NOTE: https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
+	NOTE: Fixed by: https://github.com/isaacs/minimatch/commit/0d4616de9193bf1d359271662e92657bb51b2f75 (v9.0.7)
 CVE-2026-27903 (minimatch is a minimal matching utility for converting glob expression ...)
-	TODO: check
+	- node-minimatch <unfixed>
+	NOTE: https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj
+	NOTE: Fixed by: https://github.com/isaacs/minimatch/commit/0d4616de9193bf1d359271662e92657bb51b2f75 (v9.0.7)
 CVE-2026-27902 (Svelte performance oriented web framework. Prior to version 5.53.5, er ...)
 	NOT-FOR-US: Svelte
 CVE-2026-27901 (Svelte performance oriented web framework. Prior to version 5.53.5, th ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c55cfaccd1f7cfc6d7fb3a6e95b10d00f4ea831

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c55cfaccd1f7cfc6d7fb3a6e95b10d00f4ea831
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260226/d6ef5657/attachment.htm>


More information about the debian-security-tracker-commits mailing list