Skip to main content

Vendor archive

jonschlinkert CVEs

Beta · best-effort

6 CVEs tagged to vendor jonschlinkert0 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-33672

Published Mar 26, 2026

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` obj…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-33671

Published Mar 26, 2026

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted ex…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-57328

Published Sep 24, 2025

toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A Prototype Pollution vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4068

Published May 14, 2024

The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4067

Published May 14, 2024

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1