{"api_version":"v1","generated_at":"2026-10-08T15:15:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-isaacs-minimatch-b11994e29cee","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/minimatch","name":"minimatch","next_cursor":null,"observations":[{"affected":">= 10.0.0, < 10.2.3; >= 9.0.0, < 9.0.7; >= 8.0.0, < 8.0.6; >= 7.0.0, < 7.4.8; >= 6.0.0, < 6.2.2; >= 5.0.0, < 5.1.8; >= 4.0.0, < 4.2.5; < 3.1.4","affected_versions_present":true,"cve_id":"CVE-2026-27904","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27904","fixed":"For details on how to apply this update, refer to Ansible Automation Platform documentation.","last_modified":"2026-02-26T19:21:39.006Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-27904","primary_source":"","published":"2026-02-26T01:07:42.693Z"},{"affected":">= 10.0.0, < 10.2.3; >= 9.0.0, < 9.0.7; >= 8.0.0, < 8.0.6; >= 7.0.0, < 7.4.8; >= 6.0.0, < 6.2.2; >= 5.0.0, < 5.1.8; >= 4.0.0, < 4.2.5; < 3.1.3","affected_versions_present":true,"cve_id":"CVE-2026-27903","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27903","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T19:20:51.517Z","patch_url":"","primary_source":"","published":"2026-02-26T01:06:32.856Z"},{"affected":"< 10.2.1","affected_versions_present":true,"cve_id":"CVE-2026-26996","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26996","fixed":"10.2.1.","last_modified":"2026-02-20T15:34:15.151Z","patch_url":"https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5","primary_source":"","published":"2026-02-20T03:05:21.105Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"isaacs"}}
