Skip to content

fix: update picomatch to 4.0.4 to address CVE-2026-33671 ReDoS vulner…#8353

Merged
yashvanthbl137-crypto merged 1 commit intomasterfrom
fix/picomatch-security-cve-2026-33671
Mar 26, 2026
Merged

fix: update picomatch to 4.0.4 to address CVE-2026-33671 ReDoS vulner…#8353
yashvanthbl137-crypto merged 1 commit intomasterfrom
fix/picomatch-security-cve-2026-33671

Conversation

@yashvanthbl137-crypto
Copy link
Copy Markdown
Contributor

@yashvanthbl137-crypto yashvanthbl137-crypto commented Mar 26, 2026

Exception Request

Exception Type: Security CVE fix

Justification: (High, CVSS 7.5) : ReDoS vulnerability in picomatch via extglob quantifiers blocking beta release

Current Dependency: picomatch 2.3.1, 4.0.3

Upgrade To: picomatch 4.0.4

CVE Link: GHSA-c2c7-rcm5-vvqj

Ticket: CGARD-591

@yashvanthbl137-crypto yashvanthbl137-crypto marked this pull request as ready for review March 26, 2026 14:13
@yashvanthbl137-crypto yashvanthbl137-crypto requested a review from a team as a code owner March 26, 2026 14:13
@yashvanthbl137-crypto yashvanthbl137-crypto requested a review from a team March 26, 2026 14:19
Copy link
Copy Markdown

@bhargavirao24 bhargavirao24 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Approving the PR.

Image

@yashvanthbl137-crypto yashvanthbl137-crypto merged commit 146ffb7 into master Mar 26, 2026
32 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants