VDB

RHSA-2026%3A14871

RHSA-2026%3A14871 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in Lodash. A prototype pollution vulnerability in the _.unset and _.omit functions allows an attacker able to control property paths to delete methods from global prototypes. By removing essential functionalities, this can result in a denial of service.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/satellite/iop-host-inventory-frontend-rhel9@sha256:7a9a21eeb4b7d200c14a50ecfde4fa675835ec514f9b120357d787e5430776b2_amd64 as a component of Red Hat Satellite 6.18*, *, *

Timeline

  • May 7, 2026 CVE Published
  • May 13, 2026 Distribution Patch
  • May 13, 2026 Distribution Patch
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • May 13, 2026 Security Advisory
  • Jun 23, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›