Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lodash CRITICAL 9.8
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di…

Fix: 4.18.0+
Fix from $2,300 2026-03-31
Lodash MEDIUM 5.3
CVE-2026-2950

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: …

Fix: 4.17.23+
Fix from $1,600 2026-03-31
Lodash MEDIUM 5.3
CVE-2025-13465

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths w…

Fix: 4.17.23+
Fix from $1,600 2026-01-21
Lodash MEDIUM 5.3
CVE-2020-28500EPSS 7%

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Fix: 4.17.21+
Fix from $1,600 2021-02-15
Lodash HIGH 7.4
CVE-2020-8203EPSS 5%

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Fix: 4.17.20+
Fix from $1,950 2020-07-15
Lodash MEDIUM 6.5
CVE-2019-1010266

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler.…

Fix: 4.17.11+
Fix from $1,600 2019-07-17
Lodash MEDIUM 5.6
CVE-2018-16487

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or…

Fix: 4.17.11+
Fix from $1,600 2019-02-01