Red Hat released Important security updates for the nodejs:20 module across Red Hat Enterprise Linux 8 and 9 to address multiple denial-of-service flaws, including CVE-2026-26996 in the JavaScript package minimatch. The minimatch bug allows a Regular Expression Denial of Service (ReDoS) when applications pass user-controlled glob patterns to minimatch(): specially crafted patterns with many consecutive asterisks followed by a literal character not present in the target string can trigger exponential backtracking in V8 after minimatch compiles each wildcard into separate [^/]*? regex groups. Red Hat said the issue affects minimatch 10.2.0 and earlier and is fixed in 10.2.1.
The remediation was shipped through advisories RHSA-2026:7896, RHSA-2026:8339, and RHSA-2026:9711, covering RHEL 9, RHEL 8, and RHEL 9.4 Extended Update Support channels respectively. The updates rebase Node.js 20 to 20.20.2 and include npm 10.8.2, while also addressing CVE-2026-21710 in Node.js, CVE-2026-27135 in nghttp2, and CVE-2026-27904 in minimatch. Red Hat listed affected and updated builds for x86_64, aarch64, ppc64le, and s390x, including EUS, SAP Solutions, 4-year update, AUS, and Extended Life Cycle channels.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-22, Red Hat published RHSA-2026:9874, an Important security advisory for the nodejs:20 module in Red Hat Enterprise Linux 9.6 Extended Update Support and related RHEL 9.6 channels. The update released Node.js 20.20.2-2 packages and fixed CVE-2026-26996 in minimatch along with three other denial-of-service vulnerabilities in minimatch, nghttp2, and Node.js.
On 2026-04-22, Red Hat published RHSA-2026:9711, an Important security advisory for the nodejs:20 module in Red Hat Enterprise Linux 9.4 Extended Update Support and related channels. The update released Node.js 20.20.2-2 packages and fixed CVE-2026-26996 in minimatch along with three other denial-of-service vulnerabilities.
On 2026-04-15, Red Hat's Bugzilla entry 2441268 documented CVE-2026-26996 as a denial-of-service vulnerability in minimatch caused by exponential regex backtracking from crafted glob patterns. The record also noted that Red Hat advisories were addressing the issue across multiple products.
On 2026-04-15, Red Hat published RHSA-2026:8339, an Important security advisory for the nodejs:20 module in Red Hat Enterprise Linux 8. The update rebased Node.js to 20.20.2 and fixed CVE-2026-26996 in minimatch together with additional denial-of-service issues in minimatch, nghttp2, and Node.js.
On 2026-04-13, Red Hat published RHSA-2026:7896, an Important security advisory for the nodejs:20 module in Red Hat Enterprise Linux 9. The update rebased Node.js to 20.20.2 and included fixes for CVE-2026-26996 in minimatch along with three other denial-of-service vulnerabilities.
The minimatch package fixed a Regular Expression Denial of Service vulnerability affecting version 10.2.0 and earlier, caused by specially crafted glob patterns with many consecutive wildcards. The Bugzilla record states the issue was resolved in minimatch version 10.2.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.