CWE-1321
AllowedImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Abstraction: Variant · Status: Incomplete
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
919 vulnerabilities reference this CWE, most recent first.
CVE-2026-104849 (GCVE-0-2026-104849)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:17 – Updated: 2026-10-02 16:17| URL | Tags |
|---|---|
| https://github.com/tinylibs/tinypool/security/adv… | x_refsource_CONFIRM |
| https://github.com/tinylibs/tinypool/pull/135 | x_refsource_MISC |
| https://github.com/tinylibs/tinypool/commit/f4141… | x_refsource_MISC |
| https://github.com/tinylibs/tinypool/releases/tag… | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "tinypool",
"vendor": "tinylibs",
"versions": [
{
"status": "affected",
"version": "\u003c 2.1.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process\u0027s privileges. This issue is fixed in version 2.1.2."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.5,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:17:28.062Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr"
},
{
"name": "https://github.com/tinylibs/tinypool/pull/135",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/pull/135"
},
{
"name": "https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf"
},
{
"name": "https://github.com/tinylibs/tinypool/releases/tag/v2.1.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/releases/tag/v2.1.2"
}
],
"source": {
"advisory": "GHSA-85c8-ppgw-ccpr",
"discovery": "UNKNOWN"
},
"title": "Tinypool: Prototype Pollution Gadget to RCE in run() options"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104849",
"datePublished": "2026-10-02T16:17:28.062Z",
"dateReserved": "2026-10-02T14:38:43.244Z",
"dateUpdated": "2026-10-02T16:17:28.062Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104848 (GCVE-0-2026-104848)
Vulnerability from cvelistv5 – Published: 2026-10-02 16:15 – Updated: 2026-10-02 17:29- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/tinylibs/tinypool/security/adv… | x_refsource_CONFIRM |
| https://github.com/tinylibs/tinypool/pull/134 | x_refsource_MISC |
| https://github.com/tinylibs/tinypool/commit/24df4… | x_refsource_MISC |
| https://github.com/tinylibs/tinypool/releases/tag… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104848",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T17:29:00.481503Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T17:29:40.500Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "tinypool",
"vendor": "tinylibs",
"versions": [
{
"status": "affected",
"version": "\u003c 2.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process\u0027s privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.5,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T16:15:04.101Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3"
},
{
"name": "https://github.com/tinylibs/tinypool/pull/134",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/pull/134"
},
{
"name": "https://github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f8924227404fd",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f8924227404fd"
},
{
"name": "https://github.com/tinylibs/tinypool/releases/tag/v2.1.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/tinylibs/tinypool/releases/tag/v2.1.1"
}
],
"source": {
"advisory": "GHSA-5gmw-xhrv-c9v3",
"discovery": "UNKNOWN"
},
"title": "Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104848",
"datePublished": "2026-10-02T16:15:04.101Z",
"dateReserved": "2026-10-02T14:38:43.244Z",
"dateUpdated": "2026-10-02T17:29:40.500Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104183 (GCVE-0-2026-104183)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:17 – Updated: 2026-10-01 20:30- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/uhop/stream-json/security/advi… | x_refsource_CONFIRM |
| https://github.com/uhop/stream-json/commit/2f2d35… | x_refsource_MISC |
| https://github.com/uhop/stream-json/releases/tag/3.6.0 | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| uhop | stream-json |
Affected:
< 3.6.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104183",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T20:29:33.204136Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:30:54.674Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "stream-json",
"vendor": "uhop",
"versions": [
{
"status": "affected",
"version": "\u003c 3.6.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "LOW",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T20:17:21.645Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/uhop/stream-json/security/advisories/GHSA-mjw6-4jj6-33hc"
},
{
"name": "https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/commit/2f2d35bbb547306991ded6487a279154d865a358"
},
{
"name": "https://github.com/uhop/stream-json/releases/tag/3.6.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/uhop/stream-json/releases/tag/3.6.0"
}
],
"source": {
"advisory": "GHSA-mjw6-4jj6-33hc",
"discovery": "UNKNOWN"
},
"title": "stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-104183",
"datePublished": "2026-10-01T20:17:21.645Z",
"dateReserved": "2026-10-01T18:54:15.118Z",
"dateUpdated": "2026-10-01T20:30:54.674Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103918 (GCVE-0-2026-103918)
Vulnerability from cvelistv5 – Published: 2026-10-02 20:02 – Updated: 2026-10-02 20:02| URL | Tags |
|---|---|
| https://github.com/middleapi/orpc/security/adviso… | x_refsource_CONFIRM |
| https://github.com/middleapi/orpc/pull/1727 | x_refsource_MISC |
| https://github.com/middleapi/orpc/commit/26314dfb… | x_refsource_MISC |
| https://github.com/middleapi/orpc/releases/tag/v1.14.10 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "orpc",
"vendor": "middleapi",
"versions": [
{
"status": "affected",
"version": "\u003c 1.14.10"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client that can reach a procedure with an object or record input can supply __proto__ to replace the prototype of the returned request object, allowing attacker-controlled inherited values to reach application lookups. For object schemas, keys such as constructor, toString, and __proto__ can instead resolve inherited members as Zod schemas and cause an unhandled TypeError before validation. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and the availability effect is limited to crafted requests rather than persistent process-wide state. This issue is fixed in version 1.14.10."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T20:02:50.946Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/middleapi/orpc/security/advisories/GHSA-gcgf-fh7c-8gf2",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/middleapi/orpc/security/advisories/GHSA-gcgf-fh7c-8gf2"
},
{
"name": "https://github.com/middleapi/orpc/pull/1727",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/pull/1727"
},
{
"name": "https://github.com/middleapi/orpc/commit/26314dfb443237c495116c5794d3d30a7a22c570",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/commit/26314dfb443237c495116c5794d3d30a7a22c570"
},
{
"name": "https://github.com/middleapi/orpc/releases/tag/v1.14.10",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/releases/tag/v1.14.10"
}
],
"source": {
"advisory": "GHSA-gcgf-fh7c-8gf2",
"discovery": "UNKNOWN"
},
"title": "@orpc/zod: Prototype injection in smart coercion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103918",
"datePublished": "2026-10-02T20:02:50.946Z",
"dateReserved": "2026-10-01T14:20:19.153Z",
"dateUpdated": "2026-10-02T20:02:50.946Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103036 (GCVE-0-2026-103036)
Vulnerability from cvelistv5 – Published: 2026-10-02 19:59 – Updated: 2026-10-02 20:00| URL | Tags |
|---|---|
| https://github.com/middleapi/orpc/security/adviso… | x_refsource_CONFIRM |
| https://github.com/middleapi/orpc/pull/1726 | x_refsource_MISC |
| https://github.com/middleapi/orpc/commit/8a352622… | x_refsource_MISC |
| https://github.com/middleapi/orpc/releases/tag/v1.14.9 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "orpc",
"vendor": "middleapi",
"versions": [
{
"status": "affected",
"version": "\u003c 1.14.9"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to resolve schema.properties entries through the prototype chain. A remote client that can reach a procedure with an object input schema can supply __proto__ to replace the prototype of the single coerced request object, or supply Object.prototype member names such as constructor and toString so inherited values are treated as sub-schemas and pass the coercer\u0027s satisfaction check. Attacker-controlled inherited properties can consequently affect handler, Object.assign, or configuration lookups, while legitimate __proto__ properties are dropped. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and downstream schema validation still runs. This issue is fixed in version 1.14.9."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T20:00:46.620Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/middleapi/orpc/security/advisories/GHSA-4h5r-cv8j-4456",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/middleapi/orpc/security/advisories/GHSA-4h5r-cv8j-4456"
},
{
"name": "https://github.com/middleapi/orpc/pull/1726",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/pull/1726"
},
{
"name": "https://github.com/middleapi/orpc/commit/8a352622e756e8956311f5836cd5c5b9219c0666",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/commit/8a352622e756e8956311f5836cd5c5b9219c0666"
},
{
"name": "https://github.com/middleapi/orpc/releases/tag/v1.14.9",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/middleapi/orpc/releases/tag/v1.14.9"
}
],
"source": {
"advisory": "GHSA-4h5r-cv8j-4456",
"discovery": "UNKNOWN"
},
"title": "@orpc/json-schema: Prototype injection in smart coercion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103036",
"datePublished": "2026-10-02T19:59:23.947Z",
"dateReserved": "2026-09-29T21:13:24.032Z",
"dateUpdated": "2026-10-02T20:00:46.620Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102992 (GCVE-0-2026-102992)
Vulnerability from cvelistv5 – Published: 2026-09-30 19:50 – Updated: 2026-09-30 20:47- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/piscinajs/piscina/security/adv… | x_refsource_CONFIRM |
| https://github.com/piscinajs/piscina/commit/0cb12… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/commit/2f69f… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/commit/5be7b… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/commit/bebbd… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/releases/tag… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/releases/tag… | x_refsource_MISC |
| https://github.com/piscinajs/piscina/releases/tag… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102992",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T20:47:28.974211Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T20:47:49.562Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "piscina",
"vendor": "piscinajs",
"versions": [
{
"status": "affected",
"version": "\u003c 4.9.4"
},
{
"status": "affected",
"version": "\u003e= 5.0.0, \u003c 5.3.2"
},
{
"status": "affected",
"version": "\u003e= 6.0.0-rc.1, \u003c 6.0.0-rc.5"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:50:18.036Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx"
},
{
"name": "https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f"
},
{
"name": "https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72"
},
{
"name": "https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7"
},
{
"name": "https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6"
},
{
"name": "https://github.com/piscinajs/piscina/releases/tag/v4.9.4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/releases/tag/v4.9.4"
},
{
"name": "https://github.com/piscinajs/piscina/releases/tag/v5.3.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/releases/tag/v5.3.2"
},
{
"name": "https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5"
}
],
"source": {
"advisory": "GHSA-67c8-pqhq-4rmx",
"discovery": "UNKNOWN"
},
"title": "piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102992",
"datePublished": "2026-09-30T19:50:18.036Z",
"dateReserved": "2026-09-29T20:46:08.334Z",
"dateUpdated": "2026-09-30T20:47:49.562Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102600 (GCVE-0-2026-102600)
Vulnerability from cvelistv5 – Published: 2026-09-29 15:23 – Updated: 2026-09-29 16:28| URL | Tags |
|---|---|
| https://github.com/socketio/socket.io/security/ad… | x_refsource_CONFIRM |
| https://github.com/socketio/socket.io/commit/830e… | x_refsource_MISC |
| https://github.com/socketio/socket.io/releases/ta… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| socketio | socket.io |
Affected:
< 0.1.1
|
|
| @socket.io | cluster-engine |
Affected:
< 0.1.1
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102600",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T16:27:29.573677Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:28:28.476Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "socket.io",
"vendor": "socketio",
"versions": [
{
"status": "affected",
"version": "\u003c 0.1.1"
}
]
},
{
"product": "cluster-engine",
"vendor": "@socket.io",
"versions": [
{
"status": "affected",
"version": "\u003c 0.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T15:23:15.857Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/socketio/socket.io/security/advisories/GHSA-wfpm-5gcm-94cg",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/socketio/socket.io/security/advisories/GHSA-wfpm-5gcm-94cg"
},
{
"name": "https://github.com/socketio/socket.io/commit/830e3642ebb8dc3784eb749b0a004fe2b932b429",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/socketio/socket.io/commit/830e3642ebb8dc3784eb749b0a004fe2b932b429"
},
{
"name": "https://github.com/socketio/socket.io/releases/tag/@socket.io/cluster-engine@0.1.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/socketio/socket.io/releases/tag/@socket.io/cluster-engine@0.1.1"
}
],
"source": {
"advisory": "GHSA-wfpm-5gcm-94cg",
"discovery": "UNKNOWN"
},
"title": "Socket.IO: Prototype Pollution via Unsafe Client Session Lookup"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102600",
"datePublished": "2026-09-29T15:23:15.857Z",
"dateReserved": "2026-09-29T14:18:02.920Z",
"dateUpdated": "2026-09-29T16:28:28.476Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101909 (GCVE-0-2026-101909)
Vulnerability from cvelistv5 – Published: 2026-09-28 17:42 – Updated: 2026-10-01 14:44- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/axios/axios/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC |
| https://github.com/axios/axios/commit/d19040bda7a… | x_refsource_MISC |
| https://github.com/axios/axios/commit/d29be181f85… | x_refsource_MISC |
| https://github.com/axios/axios/releases/tag/v0.34.0 | x_refsource_MISC |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101909",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:44:04.557595Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:44:46.040Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "axios",
"vendor": "axios",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.15.1, \u003c 1.20.0"
},
{
"status": "affected",
"version": "\u003e= 0.28.0, \u003c 0.34.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:42:40.203Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"
},
{
"name": "https://github.com/axios/axios/pull/11141",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/pull/11141"
},
{
"name": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
},
{
"name": "https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b"
},
{
"name": "https://github.com/axios/axios/releases/tag/v0.34.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/releases/tag/v0.34.0"
},
{
"name": "https://github.com/axios/axios/releases/tag/v1.20.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/releases/tag/v1.20.0"
}
],
"source": {
"advisory": "GHSA-x97p-jq2g-jp4f",
"discovery": "UNKNOWN"
},
"title": "Axios: Prototype Pollution Gadget in axios toFormData Options"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-101909",
"datePublished": "2026-09-28T17:42:40.203Z",
"dateReserved": "2026-09-28T15:55:37.907Z",
"dateUpdated": "2026-10-01T14:44:46.040Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101908 (GCVE-0-2026-101908)
Vulnerability from cvelistv5 – Published: 2026-09-28 17:38 – Updated: 2026-09-28 18:15- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/axios/axios/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC |
| https://github.com/axios/axios/commit/d19040bda7a… | x_refsource_MISC |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101908",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T18:14:22.792981Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T18:15:41.687Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "axios",
"vendor": "axios",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.7.0, \u003c 1.20.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:38:55.303Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8"
},
{
"name": "https://github.com/axios/axios/pull/11141",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/pull/11141"
},
{
"name": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
},
{
"name": "https://github.com/axios/axios/releases/tag/v1.20.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/releases/tag/v1.20.0"
}
],
"source": {
"advisory": "GHSA-vh66-26gq-q6x8",
"discovery": "UNKNOWN"
},
"title": "Axios: Prototype pollution gadget in fetch adapter can alter outbound requests"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-101908",
"datePublished": "2026-09-28T17:38:55.303Z",
"dateReserved": "2026-09-28T15:55:37.907Z",
"dateUpdated": "2026-09-28T18:15:41.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101905 (GCVE-0-2026-101905)
Vulnerability from cvelistv5 – Published: 2026-09-28 17:31 – Updated: 2026-10-01 14:42| URL | Tags |
|---|---|
| https://github.com/axios/axios/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC |
| https://github.com/axios/axios/commit/d19040bda7a… | x_refsource_MISC |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101905",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:42:12.150893Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:42:48.243Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "axios",
"vendor": "axios",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.15.2, \u003c 1.20.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-441",
"description": "CWE-441: Unintended Proxy or Intermediary (\u0027Confused Deputy\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:31:00.916Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"
},
{
"name": "https://github.com/axios/axios/pull/11141",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/pull/11141"
},
{
"name": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
},
{
"name": "https://github.com/axios/axios/releases/tag/v1.20.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/releases/tag/v1.20.0"
}
],
"source": {
"advisory": "GHSA-m8m8-qj5v-23w3",
"discovery": "UNKNOWN"
},
"title": "Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-101905",
"datePublished": "2026-09-28T17:31:00.916Z",
"dateReserved": "2026-09-28T15:55:37.907Z",
"dateUpdated": "2026-10-01T14:42:48.243Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
Mitigation
By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
Mitigation
Strategy: Input Validation
When handling untrusted objects, validating using a schema can be used.
Mitigation
By using an object without prototypes (via Object.create(null) ), adding object prototype attributes by accessing the prototype via the special attributes becomes impossible, mitigating this weakness.
Mitigation
Map can be used instead of objects in most cases. If Map methods are used instead of object attributes, it is not possible to access the object prototype or modify it.
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. An attacker with the ability to access functionality not properly constrained by ACLs can obtain sensitive information and possibly compromise the entire application. Such an attacker can access resources that must be available only to users at a higher privilege level, can access management sections of the application, or can run queries for data that they otherwise not supposed to.
CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels
An attacker exploits a weakness in the configuration of access controls and is able to bypass the intended protection that these measures guard against and thereby obtain unauthorized access to the system or network. Sensitive functionality should always be protected with access controls. However configuring all but the most trivial access control systems can be very complicated and there are many opportunities for mistakes. If an attacker can learn of incorrectly configured access security settings, they may be able to exploit this in an attack.
CAPEC-77: Manipulating User-Controlled Variables
This attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An adversary can override variables leveraging user-supplied, untrusted query variables directly used on the application server without any data sanitization. In extreme cases, the adversary can change variables controlling the business logic of the application. For instance, in languages like PHP, a number of poorly set default configurations may allow the user to override variables.