WS-2018-0589
Published:May 14, 2026
Updated:May 14, 2026
A Regular Expression vulnerability was found in nwmatcher before 1.4.4. The fix replacing multiple repeated instances of the "\s*" pattern.
Affected Packages
nwmatcher (CDN_JS):
Affected version(s) >=1.2.5 <1.4.4Fix Suggestion:
Update to version 1.4.4jsdom (CONDA):
Affected version(s) =11.0.0 <11.11.0Fix Suggestion:
Update to version 11.11.0nwmatcher (NPM):
Affected version(s) >=1.2.5 <1.4.4Fix Suggestion:
Update to version 1.4.4jadu/pulsar (PHP):
Affected version(s) >=dev-favicon-editor-configure-validaton <dev-feature/remove-extensionsFix Suggestion:
Update to version dev-feature/remove-extensionsjadu/pulsar (PHP):
Affected version(s) >=7.0.2 <dev-dependabot/npm_and_yarn/docs/node-sass-and-docusaurus-plugin-sass-8.0.0Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/docs/node-sass-and-docusaurus-plugin-sass-8.0.0jadu/pulsar (PHP):
Affected version(s) =dev-playground/workflow-designer <dev-poc-image-managementFix Suggestion:
Update to version dev-poc-image-managementjadu/pulsar (PHP):
Affected version(s) >=3.5.1 <dev-snyk-fix-b6f522fbf81faca176348eeda304d3c4Fix Suggestion:
Update to version dev-snyk-fix-b6f522fbf81faca176348eeda304d3c4jadu/pulsar (PHP):
Affected version(s) =dev-cms-a11y-develop <dev-read-only-a11yFix Suggestion:
Update to version dev-read-only-a11yjadu/pulsar (PHP):
Affected version(s) =6.0.0 <dev-snyk-upgrade-f2992393e8ee38c4042a6d738a26a0ffFix Suggestion:
Update to version dev-snyk-upgrade-f2992393e8ee38c4042a6d738a26a0ffjadu/pulsar (PHP):
Affected version(s) =dev-CMS/personalisation <dev-SUP025952Fix Suggestion:
Update to version dev-SUP025952jadu/pulsar (PHP):
Affected version(s) =dev-landmark-layout <dev-lodashFix Suggestion:
Update to version dev-lodashjadu/pulsar (PHP):
Affected version(s) >=6.11.1 <dev-snyk-fix-2236754c7dd2c1d32c81bb4afc1ea7f8Fix Suggestion:
Update to version dev-snyk-fix-2236754c7dd2c1d32c81bb4afc1ea7f8jadu/pulsar (PHP):
Affected version(s) =dev-poc-symfony-upgrade <dev-purpleFix Suggestion:
Update to version dev-purplejadu/pulsar (PHP):
Affected version(s) >=4.2.0 <dev-dependabot/npm_and_yarn/handlebars-4.7.7Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/handlebars-4.7.7jadu/pulsar (PHP):
Affected version(s) =dev-CMS/a11y <dev-a11y-filterbarFix Suggestion:
Update to version dev-a11y-filterbarjadu/pulsar (PHP):
Affected version(s) =dev-master <dev-modal-lexiconFix Suggestion:
Update to version dev-modal-lexiconjadu/pulsar (PHP):
Affected version(s) =4.1.0 <dev-dependabot/npm_and_yarn/docs/http-cache-semantics-4.1.1Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/docs/http-cache-semantics-4.1.1jadu/pulsar (PHP):
Affected version(s) =dev-develop-kimble <dev-docsFix Suggestion:
Update to version dev-docsjadu/pulsar (PHP):
Affected version(s) >=8.1.0 <dev-dependabot/npm_and_yarn/docs/postcss-8.4.31Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/docs/postcss-8.4.31jadu/pulsar (PHP):
Affected version(s) =9.0.0 <dev-snyk-upgrade-294cc9393d2ef5f9358959897b19a074Fix Suggestion:
Update to version dev-snyk-upgrade-294cc9393d2ef5f9358959897b19a074jadu/pulsar (PHP):
Affected version(s) >=5.2.0 <dev-dependabot/npm_and_yarn/docs/semver-5.7.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/docs/semver-5.7.2jadu/pulsar (PHP):
Affected version(s) =dev-1085_rule-block-contrast <dev-1107_form-compound-mobile-spacingFix Suggestion:
Update to version dev-1107_form-compound-mobile-spacingjadu/pulsar (PHP):
Affected version(s) =5.0.0 <dev-snyk-upgrade-07a5b6d57b29d3533ba50ff5882a5e53Fix Suggestion:
Update to version dev-snyk-upgrade-07a5b6d57b29d3533ba50ff5882a5e53jadu/pulsar (PHP):
Affected version(s) >=6.0.1 <dev-dependabot/npm_and_yarn/elliptic-6.5.4Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/elliptic-6.5.4jadu/pulsar (PHP):
Affected version(s) =dev-file-picker <dev-filter-truncateFix Suggestion:
Update to version dev-filter-truncateoburatongoi/productivity (PHP):
Affected version(s) >=0.3.26 <0.3.36Fix Suggestion:
Update to version 0.3.36jadu/pulsar (PHP):
Affected version(s) >=3.4.0 <dev-dependabot/npm_and_yarn/jquery-3.5.0Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/jquery-3.5.0jadu/pulsar (PHP):
Affected version(s) >=5.0.1 <dev-dependabot/npm_and_yarn/glob-parent-and-grunt-browserify-and-matchdep-and-mochify-5.1.2Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/glob-parent-and-grunt-browserify-and-matchdep-and-mochify-5.1.2jadu/pulsar (PHP):
Affected version(s) >=6.6.0 <dev-dependabot/npm_and_yarn/qs-and-browser-sync-and-grunt-gh-pages-6.11.0Fix Suggestion:
Update to version dev-dependabot/npm_and_yarn/qs-and-browser-sync-and-grunt-gh-pages-6.11.0Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.3
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
NONE
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
3.7
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW