Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jonschlinkert

First CVE: May 14, 2024Active for: 2 yearsTotal CVEs: 6

Jonschlinkert maintains a focused collection of JavaScript utility libraries—including picomatch, braces, and micromatch—that perform pattern matching, string parsing, and configuration file handling in Node.js and browser environments. The durable signal across these libraries centers on input-handling and resource-consumption weaknesses: prototype pollution, inefficient regular expression evaluation, and uncontrolled algorithmic complexity that can arise when parsing untrusted patterns or configuration data. Defenders should review dependencies on these parsing utilities for exposure to malformed or adversarial input; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jonschlinkert over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2024
2 years ago
Most Recent CVE
Mar 26, 2026
120 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33671HIGH
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted ext
Mar 26, 20267.531NONO
CVE-2025-57328HIGH
toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A Prototype Pollution vulnerabilit
Sep 24, 20257.525NONO
CVE-2024-4068HIGH
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious u
May 14, 20247.525NONO
CVE-2026-33672MEDIUM
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` obje
Mar 26, 20265.324NONO
CVE-2025-25975HIGH
An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function
Mar 12, 20257.520NONO
CVE-2024-4067MEDIUM
The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because t
May 14, 20245.319NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jonschlinkert.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jonschlinkert — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jonschlinkert's Products

View all 3 CNAs →

Top CWEs