CVE-2026-33672

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update

mediumEPSS 0.4%

Description

A flaw was found in picomatch, a JavaScript glob matcher. A remote attacker could exploit a method injection vulnerability by providing specially crafted POSIX bracket expressions, such as [[:constructor:]]. This allows the attacker to inject inherited method names into generated regular expressions, leading to incorrect glob matching behavior. This issue can cause security-relevant logic errors in applications that use picomatch for filtering, validation, or access control, potentially compromising data integrity.

Metrics

Severity
medium
no public PoC known
5.3
Source: nvd-v3
34.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-18 18:22 UTC
CWE-1321

Weakness classes (CWE)

  • CWE-1321Variant

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.25.0

  • go-jose_project

    go-jose3.0.0 – 3.0.5

  • go-jose_project

    go-jose4.0.0 – 4.1.4

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • golang

    net0.55.0

  • grpc

    grpc1.79.3

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • nodeca

    js-yaml4.0.0 – 4.2.0

  • nodeca

    js-yaml3.15.0

References & sources

Linked CVEs

Show 17 more CVEs
IDCVE-2026-33672