CVE-2026-33672
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update
Description
A flaw was found in picomatch, a JavaScript glob matcher. A remote attacker could exploit a method injection vulnerability by providing specially crafted POSIX bracket expressions, such as [[:constructor:]]. This allows the attacker to inject inherited method names into generated regular expressions, leading to incorrect glob matching behavior. This issue can cause security-relevant logic errors in applications that use picomatch for filtering, validation, or access control, potentially compromising data integrity.
Metrics
Weakness classes (CWE)
CWE-1321Variant
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
bitnami
golang1.25.0
go-jose_project
go-jose3.0.0 – 3.0.5
go-jose_project
go-jose4.0.0 – 4.1.4
golang
go1.25.0 – 1.25.6
golang
go1.24.12
golang
net0.55.0
grpc
grpc1.79.3
IBM
App Connect EnterpriseCD 13.4.0
IBM
App Connect EnterpriseLTS 12.0.26
IBM
App Connect EnterpriseLTS 13.4.0
IBM
Concert< 3.0.0
fixed in 3.0.0
nodeca
js-yaml4.0.0 – 4.2.0
nodeca
js-yaml3.15.0
References & sources
- https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvqweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-1527advisory
- https://hackerone.com/reports/3487198web
- https://cna.openjsf.org/security-advisories.htmlweb
- https://github.com/nodejs/undicipackage
- https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6web
- https://nvd.nist.gov/vuln/detail/CVE-2026-13676advisory
- https://github.com/fastify/fast-uri/pull/188web
- https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05web
- https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bdweb
- https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1dweb
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.jsonweb
- https://github.com/fastify/fast-uri/releases/tag/v4.0.1web
- https://github.com/fastify/fast-uri/releases/tag/v3.1.3web
- https://github.com/fastify/fast-uri/releases/tag/v2.4.2web
- https://github.com/fastify/fast-uripackage
- https://bugzilla.redhat.com/show_bug.cgi?id=2494197web
- https://access.redhat.com/security/cve/CVE-2026-13676web
- https://access.redhat.com/errata/RHSA-2026:48126web
- https://access.redhat.com/errata/RHSA-2026:48124web
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9679
A flaw was found in undici.
mediumCVSSv3 5.9 - CVE-2026-9358
A flaw was found in postcss.
mediumCVSSv3 4.3 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-6733
A flaw was found in undici.
lowCVSSv3 3.7 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-6321
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-59869
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-53550
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
mediumCVSSv3 5.3 - CVE-2026-48801
A flaw was found in linkify-it, a library for recognizing links with full Unicode support.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-45736
A flaw was found in ws, an open source WebSocket client and server for Node.js.
highCVSSv3 7.5 - CVE-2026-45409
A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications.
mediumCVSSv3 5.3 - CVE-2026-42342
A flaw was found in React Router and @remix-run/server-runtime.
highCVSSv3 7.5 - CVE-2026-41907
A flaw was found in uuid.
high - CVE-2026-41650
A flaw was found in fast-xml-parser.
mediumCVSSv3 6.1 - CVE-2026-41305
A flaw was found in PostCSS.
mediumCVSSv3 6.1 - CVE-2026-40181
A flaw was found in React Router.
mediumCVSSv3 6.1 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-35469
A flaw was found in the SPDY streaming code used by Kubelet, CRI-O, and kube-apiserver.
highCVSSv3 6.5 - CVE-2026-34986
A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) objects.
highCVSSv3 7.5 - CVE-2026-34043
A flaw was found in serialize-javascript.
mediumCVSSv3 5.9 - CVE-2026-33750
A flaw was found in the brace-expansion library, a component used for generating strings based on patterns.
mediumCVSSv3 6.5 - CVE-2026-33671
A flaw was found in Picomatch, a JavaScript glob matcher.
highCVSSv3 7.5
Show 17 more CVEs
- CVE-2026-33349
A flaw was found in fast-xml-parser.
mediumCVSSv3 5.9 - CVE-2026-33186
A flaw was found in gRPC-Go, the Go language implementation of gRPC.
criticalCVSSv3 9.1 - CVE-2026-25645
A flaw was found in the `requests` HTTP library, specifically in the `requests.utils.extract_zipped_paths()` function, which is used to l…
mediumCVSSv3 4.4 - CVE-2026-2229
A flaw was found in the undici WebSocket client.
highCVSSv3 7.5 - CVE-2026-22036
A flaw was found in Undici, an HTTP/1.1 client for Node.js.
mediumCVSSv3 5.9 - CVE-2026-1527
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 4.6 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1525
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 6.5 - CVE-2026-13676
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-13149
A flaw was found in brace-expansion.
high - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2026-11525
A flaw was found in undici.
lowCVSSv3 3.7 - CVE-2025-68470
An open redirect flaw has been discovered in the react-router npm library.
mediumCVSSv3 6.5 - CVE-2025-64718
A prototype pollution flaw has been discovered in the js-yaml npm library.
mediumCVSSv3 5.3 - CVE-2025-61729
A flaw was found in golang.
highCVSSv3 7.5 - CVE-2025-61726
The net/url package does not set a limit on the number of query parameters in a query.
highCVSSv3 7.5