Skip to content

Urgent - Security Vulnerability #19460

Description

@Sydney-o9

Description

Summary

@sentry/node depends on minimatch ^9.0.3, which has a known ReDoS vulnerability.

Vulnerability

  • CVE: GHSA-3ppc-4f35-3m26
  • Severity: High
  • Issue: ReDoS via repeated wildcards with non-matching literal in pattern
  • Fixed in: minimatch 10.2.1+

Request

Please upgrade minimatch dependency from ^9.0.3 to ^10.2.1 in @sentry/node.

Impact

Affects @sentry/nextjs and all packages depending on @sentry/node.

References

GHSA-3ppc-4f35-3m26

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions