The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Dec 13, 2024 | Dec 10, 2024 |
| Debian | — | No solution existsUpgrade node-micromatch | May 15, 2025 | May 14, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 14, 2024 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.1.7Upgrade Splunk Enterprise to version 9.2.4Upgrade Splunk Enterprise to version 9.3.2 | Sep 30, 2025 | May 13, 2024 |
| Suse | — | Upgrade pgadmin4Upgrade velociraptorUpgrade pgadmin4-docUpgrade pgadmin4-web-uwsgiUpgrade velociraptor-clientUpgrade pgadmin4-desktopUpgrade system-user-pgadminUpgrade pgadmin4-cloudUpgrade system-user-velociraptor | Oct 30, 2024 | May 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub