Gulpjs maintains a focused set of build-automation and file-handling utility libraries, including glob-parent and copy-props, that are embedded across JavaScript development toolchains and automation pipelines. The durable signal centers on resource-consumption and regular-expression handling issues endemic to pattern-matching and file-operation code, rather than a broad platform exposure; live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gulpjs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28503CRITICAL The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality. | Mar 23, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-35065HIGH The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression. | Dec 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-28469HIGH This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator. | Jun 3, 2021 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gulpjs.
Media articles that mention a CVE ID that affects a product developed by Gulpjs — matched by CVE ID, not by vendor name.