StackRadar

CVE-2026-27903

High

Advisory

Published 26 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
792
of 17,787 indexed, latest versions
Container images
835
deployed by those charts
Fix available
1 of 2
affected packages

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Carried by container images the latest versions of 792 of 17,787 indexed charts deploy, on 835 images.

Affected packageAffected versionsFixed inImages
minimatchnpm0.3.0, 1.0.0, 2.0.10, 3.0.0+21 more3.1.3, 4.2.5, 5.1.8, 6.2.2+2 more835
node-minimatchdeb1.0.0-1, 3.0.4-3, 3.0.4-3+deb10u1build0.18.04.1, 3.0.4-4+3 moreno fix listed7
OSV records
DEBIAN-CVE-2026-27903GHSA-7r86-cg39-jmmjUBUNTU-CVE-2026-27903

Charts affected

792 by stars
ChartLatestAffected imagesRadar Score
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
minimatch@3.1.2
3.1.3

Open the chart page →

2,178
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
minimatch@3.0.4
3.1.3

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
minimatch@3.0.4
3.1.3

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubebb/tdsf-portal:v5.7.0258458311bc9
minimatch@3.0.4
3.1.3

Open the chart page →

6,490
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
minimatch@6.2.0
6.2.2

Open the chart page →

13,819
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
minimatch@9.0.5
9.0.7

Open the chart page →

8,405
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
minimatch@9.0.5
9.0.7

Open the chart page →

2,548
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
minimatch@9.0.3
9.0.7

Open the chart page →

6,356
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
minimatch@9.0.5
9.0.7

Open the chart page →

2,509
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
minimatch@3.0.4
3.1.3
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
minimatch@3.0.4
3.1.3

Open the chart page →

26,018
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
minimatch@3.0.4
3.1.3

Open the chart page →

9,378
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
minimatch@3.0.4
3.1.3

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
minimatch@3.1.2
3.1.3

Open the chart page →

2,008
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
minimatch@5.1.6
5.1.8

Open the chart page →

16,877
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
minimatch@9.0.5
9.0.7
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
minimatch@9.0.3
9.0.7

Open the chart page →

20,204
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
minimatch@3.0.4
3.1.3

Open the chart page →

1,614
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
minimatch@3.1.2
3.1.3

Open the chart page →

2,685
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
minimatch@9.0.5
9.0.7

Open the chart page →

1,119
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
minimatch@3.1.2
3.1.3

Open the chart page →

3,555
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
stremio/server:latest3dc145603def
minimatch@3.1.2
3.1.3

Open the chart page →

2,600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
minimatch@9.0.3
9.0.7

Open the chart page →

33,242
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
minimatch@9.0.5
9.0.7

Open the chart page →

1,344
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
minimatch@3.1.2
3.1.3

Open the chart page →

4,232
lgtv2mqttleprechaun-charts0.1.11 of 1See more

lgtv2mqtt leprechaun-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
minimatch@3.0.4
3.1.3

Open the chart page →

1,062
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
minimatch@9.0.5
9.0.7

Open the chart page →

37,942
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
minimatch@9.0.5
9.0.7

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
minimatch@10.1.1
10.2.3

Open the chart page →

1,391
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
minimatch@5.0.1
5.1.8

Open the chart page →

5,905
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
minimatch@9.0.3
9.0.7

Open the chart page →

33,242
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
minimatch@3.0.4
3.1.3

Open the chart page →

9,880
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
minimatch@9.0.5
9.0.7

Open the chart page →

1,490
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
minimatch@9.0.5
9.0.7
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
minimatch@9.0.5
9.0.7

Open the chart page →

2,774
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
minimatch@3.0.3
3.1.3

Open the chart page →

5,786
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
minimatch@3.0.4
node-minimatch@3.0.4-4
3.1.3
no fix listed

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
minimatch@3.0.4
3.1.3

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
minimatch@3.0.4
3.1.3

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
minimatch@3.0.4
3.1.3

Open the chart page →

3,651
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
minimatch@9.0.4
9.0.7

Open the chart page →

4,647
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
minimatch@3.1.2
3.1.3

Open the chart page →

9,774
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
minimatch@9.0.5
9.0.7

Open the chart page →

24,400
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
minimatch@9.0.5
9.0.7

Open the chart page →

10,897
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
minimatch@3.1.2
3.1.3

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
minimatch@3.0.4
3.1.3

Open the chart page →

5,287
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
minimatch@10.1.1
10.2.3

Open the chart page →

8,303
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
minimatch@3.0.4
3.1.3

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
minimatch@5.0.1
5.1.8

Open the chart page →

29,588
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
minimatch@9.0.5
9.0.7

Open the chart page →

9,668
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
minimatch@3.0.4
3.1.3

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
minimatch@3.0.4
3.1.3

Open the chart page →

7,027
littlelink-servermhamzahkhanVerified publisher1.0.01 of 1See more

littlelink-server mhamzahkhan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27903.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
minimatch@9.0.3
9.0.7

Open the chart page →

887

Container images carrying it

835 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
chainsafe/lodestar:v1.27.07b9fe4aa8073
minimatch@9.0.3
9.0.7
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
minimatch@3.1.2
3.1.3
1
chatwoot/chatwoot:v4.15.167ebc751c171
minimatch@3.0.4
3.1.3
1
chibisafe/chibisafe:latest836467a50792
minimatch@9.0.5
9.0.7
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
minimatch@9.0.3
9.0.7
1
chocobozzz/peertube:v8.1.5052712130691
minimatch@9.0.5
9.0.7
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
minimatch@9.0.5
9.0.7
1
cnieg/maildev:v1.1.998ee05668915
minimatch@3.0.4
3.1.3
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
minimatch@5.1.0
5.1.8
1
codercom/code-server:4.11.0-debian1e2cc688008e
minimatch@3.1.2
3.1.3
1
codercom/code-server:3.10.247605610ad8d
minimatch@3.0.4
3.1.3
1
codetogether/codetogether:latest4348c8a38752
minimatch@3.1.2
3.1.3
1
coldatom/containers-security-api:latesteae9e82da080
minimatch@3.1.2
3.1.3
1
coldatom/containers-security-front:latest7c2fbbb41bcf
minimatch@5.1.6
5.1.8
1
conduction/conduction-ui-app:devd591f5e6f2a9
minimatch@3.0.4
3.1.3
1
contane/foreman:0.5.2efb98bdcc4e9
minimatch@9.0.5
9.0.7
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
minimatch@9.0.5
9.0.7
1
countly/api:25.05.4f4cc7447c4f5
minimatch@3.1.2
3.1.3
1
countly/countly-server:25.05.4e3c238248f99
minimatch@9.0.4
9.0.7
1
countly/frontend:25.05.42acbc11499b6
minimatch@3.0.8
3.1.3
1
cryptexlabs/authf:0.12.11189c07411d7c
minimatch@10.0.1
10.2.3
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
minimatch@9.0.3
9.0.7
1
cspconsole/report-processor:1.0.279a2d8840bfdf
minimatch@3.1.2
3.1.3
1
dacinfomotion/h2p:latest68fa393b472c
minimatch@3.1.2
3.1.3
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
minimatch@5.1.6
5.1.8
1
daskdev/dask-notebook:1.1.0052630f5ca04
minimatch@3.0.4
3.1.3
1
datarhei/restreamer:0.6.4655e12f9eeed
minimatch@3.0.4
3.1.3
1
davdiv/musicociel:deva85f99be882c
minimatch@9.0.3
9.0.7
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
minimatch@3.0.4
3.1.3
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
minimatch@3.0.4
3.1.3
1
dbgate/dbgate:7.2.0-alpine287077002446
minimatch@9.0.5
9.0.7
1
decayofmind/hubot:3.3.21e18e92fe694
minimatch@2.0.10
3.1.3
1
defactops/defactops-backend:1.0.2307b663c0092a
minimatch@9.0.3
9.0.7
1
denisshav/backend:latest4cc8dc5a4499
minimatch@3.0.4
3.1.3
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
minimatch@5.1.6
5.1.8
1
devkrishan001/backend:latestf1c3acadeabe
minimatch@9.0.5
9.0.7
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
minimatch@10.1.2
10.2.3
1
devravinder/node-express-app:1.0.05325a96967b5
minimatch@9.0.5
9.0.7
1
devspacecloud/ui:0.3.3deef55ff29a7
minimatch@3.0.4
3.1.3
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
minimatch@9.0.0
9.0.7
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
minimatch@3.1.2
3.1.3
1
directus/directus:11.1.0e3c8bb975350
minimatch@5.1.6
5.1.8
1
diygod/rsshub:2025-11-097a6312cac0d5
minimatch@9.0.5
9.0.7
1
docmost/docmost:0.95.041c8d777cf23
minimatch@9.0.5
9.0.7
1
documenso/documenso:v1.8.17f16a9449f18
minimatch@9.0.5
9.0.7
1
drumsergio/genieacs:1.2.16.028244054e1bf
minimatch@10.2.2
10.2.3
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
minimatch@9.0.3
9.0.7
1
ealen/echo-server:0.6.0359761caae37
minimatch@3.1.2
3.1.3
1
eameti/node-app:latestf36642affa86
minimatch@3.0.4
3.1.3
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
minimatch@9.0.5
9.0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.