VDB

GCVE-110-MAGEIA-2024-80

GCVE-110-MAGEIA-2024-80
Advisory Published
Vulnetix · Advisory published March 22, 2024
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. (CVE-2023-26136)

Affected Products

VendorProductVersionsPlatforms
Mageianodejs-tough-cookie0 (affected), 2.3.4-5.1.mga9 (unaffected), 0 (affected), 2.3.4-5.1.mga9 (unaffected)
Mageiadocker-buildx0 (affected), 0.11.2-1.mga9 (unaffected)

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›