VDB
RHSA-2026%3A14774
RHSA-2026%3A14774
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in Lodash. A prototype pollution vulnerability in the _.unset and _.omit functions allows an attacker able to control property paths to delete methods from global prototypes. By removing essential functionalities, this can result in a denial of service.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:0d1951626a35a72da71d12f819f78deccc2e4204b27e431ca74470888c612b08_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-kube-controller-manager-rhel9-operator@sha256:e13cfb65fde0317030bddbc01c8bf7fda8ef95dcdc2c9db4c572e1fdd9e13c2f_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-update-keys-rhel9@sha256:13005eb33522f259dd573ca7a39a799eebf927ab0955d0b776b8d60394e82492_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:7730eaada7f6b00d8902a9c6e3a5a628eba982f93fc3db6f8f628615ad2a116b_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-keepalived-ipfailover-rhel9@sha256:b164cb90f7ae54a2b798564f705e6e124ccbe2a655d5e2e33edba54608087709_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-docker-builder@sha256:029740439d73f427a6e015d0d75d690f85093488716132965b0451f5e15fdeba_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sdn-rhel9@sha256:dceb28fea223a841971955941104c1afefff372094944de69c132643cf6def42_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-multus-cni@sha256:93bf60c6f558a0a7152550b5d29573e02252263f6fe3cfe7f06bd67c718de810_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-olm-catalogd-rhel8@sha256:a5519d3c2742be28e2d8b6c8a49538568e10bd042bda1265562cf1df40fd23cd_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-samples-rhel9-operator@sha256:dc7b325b559ec4b6a14234507b34abc76ddb3084fce20c45caab689ffda52832_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-configmap-reloader-rhel9@sha256:a56cd25decf5a7aa85eadb725c5314a9ca35fc8858504da28658593512ecf1d7_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-prometheus-operator-admission-webhook-rhel9@sha256:5f175ca1d9728490c5f289046525fc9862399fe2c10ceed99c15f3732f2dabff_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-monitoring-rhel9-operator@sha256:39c12d5a33a88b39495ef89c9fd43f58181288dc1652953d27999e28c6ebbaf0_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-control-plane-machine-set-rhel9-operator@sha256:2b899b15707a078847493cc682723b050cdf280c9341d5024bd27dc1306b4ce9_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel9@sha256:db34f32a3b5b3e206831091cd31eabaca3d7e38d3963194b2b82c3652cf04084_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-olm-operator-controller-rhel8@sha256:ac8ad9d0a1ceb4d046bc8e3803d019fb4b4e32131e1b8dba1ef46d03c3b82c2c_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel9@sha256:71634019c4216f401a8b1e3985cec0e5a2d2f8f27362a7164a9fcb920110e40c_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-console@sha256:664dc9299b7dd43472b6aa3cfd51b6d6efa5c1d047edc6fb7ffee6cd7968a6f9_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator@sha256:690f35d2754cbcfc46ed35e9a4f48bb40bbbfc3d350f87185a455a1fc095eed6_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-docker-registry-rhel9@sha256:8938da5f7e0bead09a08ae595b44571cff07e98ec39580989855edff997acb45_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
…and 648 more
Timeline
- May 13, 2026 CVE Published
- May 15, 2026 Security Advisory
- May 16, 2026 Distribution Patch
- May 16, 2026 Security Advisory
- May 16, 2026 Security Advisory
- May 19, 2026 Security Advisory
- Jun 5, 2026 Security Advisory
- Jun 8, 2026 Distribution Patch
- Jun 8, 2026 Security Advisory
- Jun 8, 2026 Security Advisory
- Jul 29, 2026 CVE Updated
- Jul 29, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2025-13465 advisory
- https://access.redhat.com/security/cve/CVE-2025-61726 advisory
- https://access.redhat.com/security/cve/CVE-2025-69873 advisory
- https://go.dev/cl/736711 advisory
- https://pkg.go.dev/vuln/GO-2026-4433 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-69873 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-25679 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40175 advisory
- https://access.redhat.com/security/cve/CVE-2025-61728 advisory
- https://access.redhat.com/security/cve/CVE-2025-61732 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14774.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2434431 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-61728 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-61732 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439070 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-69873 advisory
- https://access.redhat.com/security/cve/CVE-2026-40175 advisory
…and 51 more