CWE-1321
AllowedImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Abstraction: Variant · Status: Incomplete
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
938 vulnerabilities reference this CWE, most recent first.
CVE-2026-101900 (GCVE-0-2026-101900)
Vulnerability from cvelistv5 – Published: 2026-09-28 17:14 – Updated: 2026-09-28 17:49| URL | Tags |
|---|---|
| https://github.com/axios/axios/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC |
| https://github.com/axios/axios/commit/d19040bda7a… | x_refsource_MISC |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101900",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:48:51.957700Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:49:13.106Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "axios",
"vendor": "axios",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.12.0, \u003c 1.20.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-693",
"description": "CWE-693: Protection Mechanism Failure",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:14:07.108Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2"
},
{
"name": "https://github.com/axios/axios/pull/11141",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/pull/11141"
},
{
"name": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
},
{
"name": "https://github.com/axios/axios/releases/tag/v1.20.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/axios/axios/releases/tag/v1.20.0"
}
],
"source": {
"advisory": "GHSA-4hqw-qxg8-jxx2",
"discovery": "UNKNOWN"
},
"title": "Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-101900",
"datePublished": "2026-09-28T17:14:07.108Z",
"dateReserved": "2026-09-28T15:55:37.906Z",
"dateUpdated": "2026-09-28T17:49:13.106Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97724 (GCVE-0-2026-97724)
Vulnerability from cvelistv5 – Published: 2026-09-25 02:09 – Updated: 2026-09-25 13:55- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| Vendor | Product | Version | |
|---|---|---|---|
| swmansion | React Native Reanimated |
Affected:
worklets-0.5.0 , < worklets-0.12.2
(custom)
cpe:2.3:a:swmansion:react_native_reanimated:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97724",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:54:55.193703Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:55:20.329Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/software-mansion/react-native-reanimated/issues/10436"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"react-native-worklets serialization"
],
"packageURL": "pkg:npm/react-native-worklets",
"platforms": [
"Android",
"iOS"
],
"product": "React Native Reanimated",
"programFiles": [
"packages/react-native-worklets/src/memory/serializable.native.ts"
],
"programRoutines": [
{
"name": "clonePlainJSObject"
}
],
"repo": "https://github.com/software-mansion/react-native-reanimated",
"vendor": "swmansion",
"versions": [
{
"lessThan": "worklets-0.12.2",
"status": "affected",
"version": "worklets-0.5.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "An application must pass attacker-controlled object data containing a \"__proto__\" property through the affected React Native Worklets serialization path."
}
],
"value": "An application must pass attacker-controlled object data containing a \"__proto__\" property through the affected React Native Worklets serialization path."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:swmansion:react_native_reanimated:*:*:*:*:*:*:*:*",
"versionEndExcluding": "worklets-0.12.2",
"versionStartIncluding": "worklets-0.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serializable.native.ts. When affected data is subsequently processed by React Native Worklets, the malformed serialized object can cause the React Native application to crash. This can result in a remotely triggered denial of service in applications that pass attacker-controlled data through the affected serialization path. In applications where the attacker-controlled data is persisted, the denial of service may persist across application restarts or repeated attempts to access the affected content."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "USER",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/R:U/V:D/RE:L",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "LOW"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321 Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T02:11:41.014Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://github.com/software-mansion/react-native-reanimated/issues/10436"
},
{
"url": "https://github.com/software-mansion/react-native-reanimated/pull/10451"
},
{
"url": "https://github.com/software-mansion/react-native-reanimated/pull/10462"
},
{
"url": "https://github.com/software-mansion/react-native-reanimated/releases/tag/worklets-0.12.2"
},
{
"url": "https://docs.swmansion.com/react-native-reanimated/"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Upgrade React Native Worklets to version 0.12.2 or later. Version 0.12.2 includes the upstream fix for unsafe handling of \"__proto__\" properties during serialization and deserialization."
}
],
"value": "Upgrade React Native Worklets to version 0.12.2 or later. Version 0.12.2 includes the upstream fix for unsafe handling of \"__proto__\" properties during serialization and deserialization."
}
],
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Applications can recursively reject or remove prototype-sensitive properties such as \"__proto__\", \"constructor\", and \"prototype\" from untrusted objects before passing them to affected Worklets APIs."
}
],
"value": "Applications can recursively reject or remove prototype-sensitive properties such as \"__proto__\", \"constructor\", and \"prototype\" from untrusted objects before passing them to affected Worklets APIs."
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-97724",
"datePublished": "2026-09-25T02:09:17.218Z",
"dateReserved": "2026-09-25T02:09:16.537Z",
"dateUpdated": "2026-09-25T13:55:20.329Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97151 (GCVE-0-2026-97151)
Vulnerability from cvelistv5 – Published: 2026-09-24 03:08 – Updated: 2026-09-24 13:02- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://raw.githubusercontent.com/mwilliamson/mam… | release-notesvendor-advisory |
| https://www.npmjs.com/package/mammoth | product |
| https://github.com/mwilliamson/mammoth.js/commit/… | patch |
| https://github.com/mwilliamson/mammoth.js/commit/… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| mwilliamson | mammoth.js |
Affected:
0 , < 1.12.2
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97151",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T13:02:06.758652Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:02:42.611Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://registry.npmjs.org",
"defaultStatus": "unaffected",
"modules": [
"docx styles reader"
],
"packageName": "mammoth",
"packageURL": "pkg:npm/mammoth",
"product": "mammoth.js",
"programFiles": [
"lib/docx/styles-reader.js"
],
"programRoutines": [
{
"name": "readStylesXml"
}
],
"repo": "https://github.com/mwilliamson/mammoth.js",
"vendor": "mwilliamson",
"versions": [
{
"lessThan": "1.12.2",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The prototype pollution itself requires no particular configuration. The less common externalFileAccess bypass additionally requires the application to convert more than one document within the same process and to return the converted HTML to the party supplying the documents.\u003cbr\u003e"
}
],
"value": "The prototype pollution itself requires no particular configuration. The less common externalFileAccess bypass additionally requires the application to convert more than one document within the same process and to return the converted HTML to the party supplying the documents."
}
],
"descriptions": [
{
"lang": "en",
"value": "mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321 Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T03:08:15.523Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"release-notes",
"vendor-advisory"
],
"url": "https://raw.githubusercontent.com/mwilliamson/mammoth.js/master/NEWS"
},
{
"tags": [
"product"
],
"url": "https://www.npmjs.com/package/mammoth"
},
{
"tags": [
"patch"
],
"url": "https://github.com/mwilliamson/mammoth.js/commit/31f0c370be4b95ac4fa285fea3be970606735f16"
},
{
"tags": [
"patch"
],
"url": "https://github.com/mwilliamson/mammoth.js/commit/2888fa158d67c1419199f152326e12a05618b53e"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Upgrade to mammoth 1.12.2 or later.\u003cbr\u003e"
}
],
"value": "Upgrade to mammoth 1.12.2 or later."
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-97151",
"datePublished": "2026-09-24T03:08:15.523Z",
"dateReserved": "2026-09-24T03:08:15.164Z",
"dateUpdated": "2026-09-24T13:02:42.611Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94646 (GCVE-0-2026-94646)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:52 – Updated: 2026-10-02 13:50| URL | Tags |
|---|---|
| https://lists.apache.org/thread/33otcgbqd27wf6qq8… | vendor-advisory |
| https://lists.apache.org/thread/5hjh0gz8wf6bo7ydx… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache Thrift |
Affected:
0 , < 0.25.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94646",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T13:50:27.730758Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T13:50:57.551Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://registry.npmjs.org",
"defaultStatus": "unaffected",
"packageName": "thrift",
"packageURL": "pkg:npm/thrift",
"product": "Apache Thrift",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "0.25.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Sylwester Lachiewicz"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes (\u0027prototype pollution\u0027) vulnerability in Apache Thrift nodejs bindings.\u003c/p\u003e\u003cp\u003eThis issue affects Apache Thrift: before 0.25.0.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 0.25.0, which fixes the issue.\u003c/p\u003e"
}
],
"value": "Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes (\u0027prototype pollution\u0027) vulnerability in Apache Thrift nodejs bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue."
}
],
"metrics": [
{
"other": {
"content": {
"text": "important"
},
"type": "Textual description of severity"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-248",
"description": "CWE-248 Uncaught exception",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1284",
"description": "CWE-1284 Improper validation of specified quantity in input",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321 Improperly controlled modification of object prototype attributes (\u0027prototype pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:52:21.192Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread/5hjh0gz8wf6bo7ydxjpqj92m42hwmfo8"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers)",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-94646",
"datePublished": "2026-10-02T11:52:21.192Z",
"dateReserved": "2026-09-21T23:13:28.097Z",
"dateUpdated": "2026-10-02T13:50:57.551Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93753 (GCVE-0-2026-93753)
Vulnerability from cvelistv5 – Published: 2026-09-18 17:51 – Updated: 2026-09-24 14:23- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/TehShrike/deepmerge/issues/273 | issue-tracking |
| https://github.com/TehShrike/deepmerge | product |
| https://github.com/TehShrike/deepmerge/blob/5b877… | technical-description |
| https://www.vulncheck.com/advisories/deepmerge-th… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93753",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T19:16:56.102337Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T19:17:03.727Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/TehShrike/deepmerge/issues/273"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/deepmerge",
"product": "deepmerge",
"vendor": "TehShrike",
"versions": [
{
"lessThanOrEqual": "4.3.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Wayde Shi (PayPal Cyber Security Team)"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object\u0027s prototype, causing applications to inherit unintended values when accessing properties without own-property checks."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:12.090Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #273",
"tags": [
"issue-tracking"
],
"url": "https://github.com/TehShrike/deepmerge/issues/273"
},
{
"tags": [
"product"
],
"url": "https://github.com/TehShrike/deepmerge"
},
{
"name": "propertyIsUnsafe() target-shape guard and the ungated target copy loop",
"tags": [
"technical-description"
],
"url": "https://github.com/TehShrike/deepmerge/blob/5b87756a5671635679001cbac72aa42f23472c81/index.js#L39-L60"
},
{
"name": "VulnCheck Advisory: deepmerge through 4.3.1 Prototype Poisoning via mergeObject",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/deepmerge-through-4.3.1-prototype-poisoning-via-mergeobject"
}
],
"title": "deepmerge through 4.3.1 Prototype Poisoning via mergeObject",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93753",
"datePublished": "2026-09-18T17:51:37.794Z",
"dateReserved": "2026-09-18T16:30:18.853Z",
"dateUpdated": "2026-09-24T14:23:12.090Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92781 (GCVE-0-2026-92781)
Vulnerability from cvelistv5 – Published: 2026-09-16 20:32 – Updated: 2026-09-21 15:50- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/BuilderIO/builder/issues/4824 | issue-tracking |
| https://github.com/BuilderIO/builder | product |
| https://github.com/BuilderIO/builder/blob/main/pa… | technical-description |
| https://github.com/BuilderIO/builder/blob/main/pa… | technical-description |
| https://www.vulncheck.com/advisories/builder-io-g… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| BuilderIO | @builder.io/sdk-react |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-vue |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-svelte |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-solid |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-qwik |
Affected:
0 , ≤ 0.25.13
(semver)
|
|
| BuilderIO | @builder.io/sdk-angular |
Affected:
0 , ≤ 0.25.13
(semver)
|
|
| BuilderIO | @builder.io/sdk-react-nextjs |
Affected:
0 , ≤ 0.25.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92781",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:50:07.571574Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:50:13.299Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/BuilderIO/builder/issues/4824"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-react",
"product": "@builder.io/sdk-react",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-vue",
"product": "@builder.io/sdk-vue",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-svelte",
"product": "@builder.io/sdk-svelte",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-solid",
"product": "@builder.io/sdk-solid",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-qwik",
"product": "@builder.io/sdk-qwik",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-angular",
"product": "@builder.io/sdk-angular",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-react-nextjs",
"product": "@builder.io/sdk-react-nextjs",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-08-25T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor\u0027s browser when the SDK processes the malicious URL."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T20:32:38.923Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #4824",
"tags": [
"issue-tracking"
],
"url": "https://github.com/BuilderIO/builder/issues/4824"
},
{
"tags": [
"product"
],
"url": "https://github.com/BuilderIO/builder"
},
{
"name": "builder.userAttributes parameters are expanded through unflatten",
"tags": [
"technical-description"
],
"url": "https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/get-content/generate-content-url.ts"
},
{
"name": "unflatten walks the dotted key path with no prototype guard",
"tags": [
"technical-description"
],
"url": "https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/helpers/flatten.ts#L60-L76"
},
{
"name": "VulnCheck Advisory: Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/builder-io-gen2-sdks-through-5.2.11-prototype-pollution-via-builder-userattributes"
}
],
"title": "Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92781",
"datePublished": "2026-09-16T20:32:38.923Z",
"dateReserved": "2026-09-16T19:22:53.825Z",
"dateUpdated": "2026-09-21T15:50:13.299Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92779 (GCVE-0-2026-92779)
Vulnerability from cvelistv5 – Published: 2026-09-16 20:32 – Updated: 2026-09-17 19:25- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/BuilderIO/builder/issues/4823 | issue-tracking |
| https://github.com/BuilderIO/builder | product |
| https://github.com/BuilderIO/builder/blob/main/pa… | technical-description |
| https://github.com/BuilderIO/builder/blob/main/pa… | technical-description |
| https://www.vulncheck.com/advisories/builder-io-g… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| BuilderIO | @builder.io/sdk-react |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-vue |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-svelte |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-solid |
Affected:
0 , ≤ 5.2.11
(semver)
|
|
| BuilderIO | @builder.io/sdk-qwik |
Affected:
0 , ≤ 0.25.13
(semver)
|
|
| BuilderIO | @builder.io/sdk-angular |
Affected:
0 , ≤ 0.25.13
(semver)
|
|
| BuilderIO | @builder.io/sdk-react-nextjs |
Affected:
0 , ≤ 0.25.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92779",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T19:16:56.428687Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T19:25:04.694Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-react",
"product": "@builder.io/sdk-react",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-vue",
"product": "@builder.io/sdk-vue",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-svelte",
"product": "@builder.io/sdk-svelte",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-solid",
"product": "@builder.io/sdk-solid",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "5.2.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-qwik",
"product": "@builder.io/sdk-qwik",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-angular",
"product": "@builder.io/sdk-angular",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/%40builder.io/sdk-react-nextjs",
"product": "@builder.io/sdk-react-nextjs",
"vendor": "BuilderIO",
"versions": [
{
"lessThanOrEqual": "0.25.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-08-25T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process including other tenants\u0027 renders."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T20:32:37.544Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #4823",
"tags": [
"issue-tracking"
],
"url": "https://github.com/BuilderIO/builder/issues/4823"
},
{
"tags": [
"product"
],
"url": "https://github.com/BuilderIO/builder"
},
{
"name": "binding keys from content JSON are used as the write path",
"tags": [
"technical-description"
],
"url": "https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/get-processed-block.ts#L84-L93"
},
{
"name": "the deep-set helper has no __proto__ guard",
"tags": [
"technical-description"
],
"url": "https://github.com/BuilderIO/builder/blob/main/packages/sdks/src/functions/set.ts#L7-L26"
},
{
"name": "VulnCheck Advisory: Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/builder-io-gen2-sdks-through-5.2.11-prototype-pollution-via-bindings"
}
],
"title": "Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92779",
"datePublished": "2026-09-16T20:32:37.544Z",
"dateReserved": "2026-09-16T19:22:53.082Z",
"dateUpdated": "2026-09-17T19:25:04.694Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91860 (GCVE-0-2026-91860)
Vulnerability from cvelistv5 – Published: 2026-09-30 13:13 – Updated: 2026-09-30 14:26- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| Vendor | Product | Version | |
|---|---|---|---|
| vaadin | vaadin |
Affected:
23.0.0 , < 23.6.14
(maven)
Affected: 24.0.0 , < 24.9.21 (maven) Affected: 24.10.0 , < 24.10.10 (maven) Affected: 25.0.0 , < 25.1.12 (maven) Affected: 25.2.0 , < 25.2.7 (maven) |
|
| vaadin | vaadin-core |
Affected:
24.7.0 , < 24.9.21
(maven)
Affected: 24.10.0 , < 24.10.10 (maven) Affected: 25.0.0 , < 25.1.12 (maven) Affected: 25.2.0 , < 25.2.7 (maven) |
|
| vaadin | vaadin-charts-flow |
Affected:
23.0.0 , < 23.6.14
(maven)
Affected: 24.0.0 , < 24.9.21 (maven) Affected: 24.10.0 , < 24.10.10 (maven) Affected: 25.0.0 , < 25.1.12 (maven) Affected: 25.2.0 , < 25.2.7 (maven) |
|
| vaadin | @vaadin/charts |
Affected:
23.0.0 , < 23.6.5
(semver)
Affected: 24.0.0 , < 24.9.18 (semver) Affected: 24.10.0 , < 24.10.5 (semver) Affected: 25.0.0 , < 25.1.12 (semver) Affected: 25.2.0 , < 25.2.9 (semver) |
|
| vaadin | @vaadin/component-base |
Affected:
24.7.0 , < 24.9.18
(semver)
Affected: 24.10.0 , < 24.10.5 (semver) Affected: 25.0.0 , < 25.1.12 (semver) Affected: 25.2.0 , < 25.2.9 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91860",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:26:16.234947Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:26:23.618Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "com.vaadin:vaadin",
"product": "vaadin",
"repo": "https://github.com/vaadin/platform",
"vendor": "vaadin",
"versions": [
{
"lessThan": "23.6.14",
"status": "affected",
"version": "23.0.0",
"versionType": "maven"
},
{
"lessThan": "24.9.21",
"status": "affected",
"version": "24.0.0",
"versionType": "maven"
},
{
"lessThan": "24.10.10",
"status": "affected",
"version": "24.10.0",
"versionType": "maven"
},
{
"lessThan": "25.1.12",
"status": "affected",
"version": "25.0.0",
"versionType": "maven"
},
{
"lessThan": "25.2.7",
"status": "affected",
"version": "25.2.0",
"versionType": "maven"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "com.vaadin:vaadin-core",
"product": "vaadin-core",
"repo": "https://github.com/vaadin/platform",
"vendor": "vaadin",
"versions": [
{
"lessThan": "24.9.21",
"status": "affected",
"version": "24.7.0",
"versionType": "maven"
},
{
"lessThan": "24.10.10",
"status": "affected",
"version": "24.10.0",
"versionType": "maven"
},
{
"lessThan": "25.1.12",
"status": "affected",
"version": "25.0.0",
"versionType": "maven"
},
{
"lessThan": "25.2.7",
"status": "affected",
"version": "25.2.0",
"versionType": "maven"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "com.vaadin:vaadin-charts-flow",
"product": "vaadin-charts-flow",
"repo": "https://github.com/vaadin/flow-components",
"vendor": "vaadin",
"versions": [
{
"lessThan": "23.6.14",
"status": "affected",
"version": "23.0.0",
"versionType": "maven"
},
{
"lessThan": "24.9.21",
"status": "affected",
"version": "24.0.0",
"versionType": "maven"
},
{
"lessThan": "24.10.10",
"status": "affected",
"version": "24.10.0",
"versionType": "maven"
},
{
"lessThan": "25.1.12",
"status": "affected",
"version": "25.0.0",
"versionType": "maven"
},
{
"lessThan": "25.2.7",
"status": "affected",
"version": "25.2.0",
"versionType": "maven"
}
]
},
{
"collectionURL": "https://registry.npmjs.org",
"defaultStatus": "unaffected",
"packageName": "@vaadin/charts",
"product": "@vaadin/charts",
"repo": "https://github.com/vaadin/web-components",
"vendor": "vaadin",
"versions": [
{
"lessThan": "23.6.5",
"status": "affected",
"version": "23.0.0",
"versionType": "semver"
},
{
"lessThan": "24.9.18",
"status": "affected",
"version": "24.0.0",
"versionType": "semver"
},
{
"lessThan": "24.10.5",
"status": "affected",
"version": "24.10.0",
"versionType": "semver"
},
{
"lessThan": "25.1.12",
"status": "affected",
"version": "25.0.0",
"versionType": "semver"
},
{
"lessThan": "25.2.9",
"status": "affected",
"version": "25.2.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://registry.npmjs.org",
"defaultStatus": "unaffected",
"packageName": "@vaadin/component-base",
"product": "@vaadin/component-base",
"repo": "https://github.com/vaadin/web-components",
"vendor": "vaadin",
"versions": [
{
"lessThan": "24.9.18",
"status": "affected",
"version": "24.7.0",
"versionType": "semver"
},
{
"lessThan": "24.10.5",
"status": "affected",
"version": "24.10.0",
"versionType": "semver"
},
{
"lessThan": "25.1.12",
"status": "affected",
"version": "25.0.0",
"versionType": "semver"
},
{
"lessThan": "25.2.9",
"status": "affected",
"version": "25.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ridwan Arefin Islam, Madiba Security Lab, Concordia University"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cspan style=\"background-color: rgba(232, 232, 232, 0.04);\"\u003eA prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component\u0027s i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003eUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\u003cbr\u003e\u003cbr\u003eProduct version\u003cbr\u003eVaadin 23.0.0 - 23.6.13\u003cbr\u003eVaadin 24.0.0 - 24.9.20\u003cbr\u003eVaadin 24.10.0 - 24.10.9\u003cbr\u003eVaadin 25.0.0 - 25.1.11\u003cbr\u003eVaadin 25.2.0 - 25.2.6\u003cbr\u003e\u003cbr\u003eMitigation\u003cbr\u003eUpgrade to 23.6.14\u003cbr\u003eUpgrade to 24.9.21\u003cbr\u003eUpgrade to 24.10.10\u003cbr\u003eUpgrade to 25.1.12\u003cbr\u003eUpgrade to 25.2.7 or newer\u003cbr\u003e\u003cbr\u003ePlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\u003cbr\u003e\u003cbr\u003eArtifacts\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003eMaven coordinates\u003c/td\u003e\u003ctd\u003eVulnerable versions\u003c/td\u003e\u003ctd\u003eFixed version\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e23.0.0 - 23.6.13\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;23.6.14\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.0.0 - 24.9.20\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.9.21\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.10.0 - 24.10.9\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.10.10\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.0.0 - 25.1.11\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.1.12\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.2.0 - 25.2.6\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.2.7\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-core\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.7.0 - 24.9.20\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.9.21\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-core\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.10.0 - 24.10.9\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.10.10\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-core\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.0.0 - 25.1.11\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.1.12\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-core\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.2.0 - 25.2.6\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.2.7\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-charts-flow\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e23.0.0 - 23.6.13\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;23.6.14\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-charts-flow\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.0.0 - 24.9.20\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.9.21\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-charts-flow\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.10.0 - 24.10.9\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.10.10\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-charts-flow\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.0.0 - 25.1.11\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.1.12\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003ecom.vaadin:vaadin-charts-flow\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.2.0 - 25.2.6\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.2.7\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003cbr\u003e\u003cbr\u003enpm packages\u003ctable\u003e\u003ctbody\u003e\u003ctr\u003e\u003ctd\u003enpm package\u003c/td\u003e\u003ctd\u003eVulnerable versions\u003c/td\u003e\u003ctd\u003eFixed version\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/charts\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e23.0.0 - 23.6.4\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;23.6.5\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/charts\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.0.0 - 24.9.17\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.9.18\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/charts\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.10.0 - 24.10.4\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.10.5\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/charts\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.0.0 - 25.1.11\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.1.12\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/charts\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.2.0 - 25.2.8\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.2.9\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/component-base\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.7.0 - 24.9.17\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.9.18\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/component-base\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e24.10.0 - 24.10.4\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;24.10.5\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/component-base\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.0.0 - 25.1.11\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.1.12\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003ctr\u003e\u003ctd\u003e@vaadin/component-base\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e25.2.0 - 25.2.8\u003cbr\u003e\u003c/td\u003e\u003ctd\u003e\u0026ge;25.2.9\u003cbr\u003e\u003c/td\u003e\u003c/tr\u003e\u003c/tbody\u003e\u003c/table\u003e\u003cbr\u003e\u003c/span\u003e"
}
],
"value": "A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component\u0027s i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.13\nVaadin 24.0.0 - 24.9.20\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.21\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.0.0 - 23.6.13 \u003e=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.20 \u003e=24.9.21\ncom.vaadin:vaadin 24.10.0 - 24.10.9 \u003e=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 \u003e=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 \u003e=25.2.7\ncom.vaadin:vaadin-core 24.7.0 - 24.9.20 \u003e=24.9.21\ncom.vaadin:vaadin-core 24.10.0 - 24.10.9 \u003e=24.10.10\ncom.vaadin:vaadin-core 25.0.0 - 25.1.11 \u003e=25.1.12\ncom.vaadin:vaadin-core 25.2.0 - 25.2.6 \u003e=25.2.7\ncom.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 \u003e=23.6.14\ncom.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 \u003e=24.9.21\ncom.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 \u003e=24.10.10\ncom.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 \u003e=25.1.12\ncom.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 \u003e=25.2.7\n\nnpm packages\nnpm package Vulnerable versions Fixed version\n@vaadin/charts 23.0.0 - 23.6.4 \u003e=23.6.5\n@vaadin/charts 24.0.0 - 24.9.17 \u003e=24.9.18\n@vaadin/charts 24.10.0 - 24.10.4 \u003e=24.10.5\n@vaadin/charts 25.0.0 - 25.1.11 \u003e=25.1.12\n@vaadin/charts 25.2.0 - 25.2.8 \u003e=25.2.9\n@vaadin/component-base 24.7.0 - 24.9.17 \u003e=24.9.18\n@vaadin/component-base 24.10.0 - 24.10.4 \u003e=24.10.5\n@vaadin/component-base 25.0.0 - 25.1.11 \u003e=25.1.12\n@vaadin/component-base 25.2.0 - 25.2.8 \u003e=25.2.9"
}
],
"impacts": [
{
"capecId": "CAPEC-77",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-77 Manipulating User-Controlled Variables"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NO",
"Recovery": "AUTOMATIC",
"Safety": "NEGLIGIBLE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "CLEAR",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "LOW"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321 Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:13:05.996Z",
"orgId": "9e0f3122-90e9-42d5-93de-8c6b98deef7e",
"shortName": "Vaadin"
},
"references": [
{
"url": "https://vaadin.com/security/cve-2026-91860"
},
{
"url": "https://github.com/vaadin/web-components/pull/12483"
},
{
"url": "https://github.com/vaadin/web-components/pull/12492"
},
{
"url": "https://github.com/vaadin/web-components/pull/12493"
},
{
"url": "https://github.com/vaadin/web-components/pull/12494"
},
{
"url": "https://github.com/vaadin/web-components/pull/12496"
},
{
"url": "https://github.com/vaadin/web-components/pull/12559"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cb\u003e\u003cspan style=\"background-color: transparent;\"\u003eUsers of affected versions should apply the following mitigation or upgrade.\u003c/span\u003e\u003c/b\u003e\u003cbr\u003e"
}
],
"value": "Users of affected versions should apply the following mitigation or upgrade."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge",
"x_generator": {
"engine": "Vulnogram 0.5.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "9e0f3122-90e9-42d5-93de-8c6b98deef7e",
"assignerShortName": "Vaadin",
"cveId": "CVE-2026-91860",
"datePublished": "2026-09-30T13:13:05.996Z",
"dateReserved": "2026-09-15T09:33:38.900Z",
"dateUpdated": "2026-09-30T14:26:23.618Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90771 (GCVE-0-2026-90771)
Vulnerability from cvelistv5 – Published: 2026-09-13 10:45 – Updated: 2026-09-24 14:21- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/hapijs/joi/issues/3150 | issue-tracking |
| https://github.com/hapijs/joi | product |
| https://github.com/hapijs/joi/blob/v18.2.8/lib/me… | technical-description |
| https://github.com/hapijs/joi/commit/5b8333c9177e… | patch |
| https://www.vulncheck.com/advisories/joi-before-1… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90771",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:02:28.580545Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:03:23.974Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/hapijs/joi/issues/3150"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/joi",
"product": "joi",
"vendor": "hapijs",
"versions": [
{
"lessThan": "17.13.8",
"status": "affected",
"version": "16.0.0",
"versionType": "semver"
},
{
"lessThan": "18.2.9",
"status": "affected",
"version": "18.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object\u0027s prototype, breaking downstream code relying on Object.prototype methods."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:52.339Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #3150",
"tags": [
"issue-tracking"
],
"url": "https://github.com/hapijs/joi/issues/3150"
},
{
"tags": [
"product"
],
"url": "https://github.com/hapijs/joi"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/hapijs/joi/blob/v18.2.8/lib/messages.js"
},
{
"tags": [
"patch"
],
"url": "https://github.com/hapijs/joi/commit/5b8333c9177e08b4ef4ed02903c2d657084e7afb"
},
{
"name": "VulnCheck Advisory: joi before 17.13.8 and 18.2.9 Prototype Pollution via messages",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/joi-before-17.13.8-and-18.2.9-prototype-pollution-via-messages"
}
],
"title": "joi before 17.13.8 and 18.2.9 Prototype Pollution via messages",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-90771",
"datePublished": "2026-09-13T10:45:42.498Z",
"dateReserved": "2026-09-13T10:14:57.680Z",
"dateUpdated": "2026-09-24T14:21:52.339Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89011 (GCVE-0-2026-89011)
Vulnerability from cvelistv5 – Published: 2026-09-10 19:56 – Updated: 2026-09-11 20:32 X_Open Source- CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
| URL | Tags |
|---|---|
| https://github.com/isomorphic-git/isomorphic-git/… | vendor-advisory |
| https://github.com/isomorphic-git/isomorphic-git/… | release-notes |
| https://github.com/isomorphic-git/isomorphic-git/… | issue-tracking |
| https://github.com/isomorphic-git/isomorphic-git/… | patch |
| https://www.vulncheck.com/advisories/isomorphic-g… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| isomorphic-git | isomorphic-git |
Affected:
0 , < 1.42.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89011",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T17:09:25.363378Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T20:32:36.479Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/isomorphic-git/isomorphic-git",
"product": "isomorphic-git",
"repo": "https://github.com/isomorphic-git/isomorphic-git",
"vendor": "isomorphic-git",
"versions": [
{
"lessThan": "1.42.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Isabel Mill"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulnCheck"
}
],
"datePublic": "2026-09-10T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing \u0027__proto__\u0027 path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as \u0027__proto__/corsProxy\u0027 to reroute all subsequent network operations through an attacker-controlled proxy, causing isomorphic-git to invoke the victim\u0027s onAuth callback and transmit credentials to the attacker when the victim calls getRemoteInfo with an attacker-supplied URL."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T19:56:25.335Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-83vg-jxvh-fx76)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/isomorphic-git/isomorphic-git/security/advisories/GHSA-83vg-jxvh-fx76"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/isomorphic-git/isomorphic-git/releases/tag/v1.42.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/isomorphic-git/isomorphic-git/pull/2426"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/isomorphic-git/isomorphic-git/commit/b3db111885230bac9a648e0a2312c65ca66f76eb"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/isomorphic-git-prototype-pollution-via-getremoteinfo"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "isomorphic-git \u003c 1.42.0 Prototype Pollution via getRemoteInfo",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-89011",
"datePublished": "2026-09-10T19:56:25.335Z",
"dateReserved": "2026-09-10T16:23:54.470Z",
"dateUpdated": "2026-09-11T20:32:36.479Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
Mitigation
By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
Mitigation
Strategy: Input Validation
When handling untrusted objects, validating using a schema can be used.
Mitigation
By using an object without prototypes (via Object.create(null) ), adding object prototype attributes by accessing the prototype via the special attributes becomes impossible, mitigating this weakness.
Mitigation
Map can be used instead of objects in most cases. If Map methods are used instead of object attributes, it is not possible to access the object prototype or modify it.
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. An attacker with the ability to access functionality not properly constrained by ACLs can obtain sensitive information and possibly compromise the entire application. Such an attacker can access resources that must be available only to users at a higher privilege level, can access management sections of the application, or can run queries for data that they otherwise not supposed to.
CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels
An attacker exploits a weakness in the configuration of access controls and is able to bypass the intended protection that these measures guard against and thereby obtain unauthorized access to the system or network. Sensitive functionality should always be protected with access controls. However configuring all but the most trivial access control systems can be very complicated and there are many opportunities for mistakes. If an attacker can learn of incorrectly configured access security settings, they may be able to exploit this in an attack.
CAPEC-77: Manipulating User-Controlled Variables
This attack targets user controlled variables (DEBUG=1, PHP Globals, and So Forth). An adversary can override variables leveraging user-supplied, untrusted query variables directly used on the application server without any data sanitization. In extreme cases, the adversary can change variables controlling the business logic of the application. For instance, in languages like PHP, a number of poorly set default configurations may allow the user to override variables.