VDB
RHSA-2026%3A2119
RHSA-2026%3A2119
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in Lodash. A prototype pollution vulnerability in the _.unset and _.omit functions allows an attacker able to control property paths to delete methods from global prototypes. By removing essential functionalities, this can result in a denial of service.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:9014acec14e4608a1b22ff2975fc98aeb29c0eaf01794d151a4c4eb80c23a88f_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:9014acec14e4608a1b22ff2975fc98aeb29c0eaf01794d151a4c4eb80c23a88f_ppc64le, registry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:9014acec14e4608a1b22ff2975fc98aeb29c0eaf01794d151a4c4eb80c23a88f_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-version-rhel9-operator@sha256:89e072a81374e62360855f81a4e0dd29461f15960342424e2b5276585fcb33a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-cluster-version-rhel9-operator@sha256:89e072a81374e62360855f81a4e0dd29461f15960342424e2b5276585fcb33a8_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-cloud-controller-manager-rhel9@sha256:c4d7582b733bf6f8b3f2257cbd13cab8fb3b7221565bf744027e33da35667b30_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-gcp-cloud-controller-manager-rhel9@sha256:c4d7582b733bf6f8b3f2257cbd13cab8fb3b7221565bf744027e33da35667b30_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-hyperkube-rhel9@sha256:80bee8b97e628b2b46eac45960cb5eba603b4f4af27aaa616c81b9c57a2fb552_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-hyperkube-rhel9@sha256:80bee8b97e628b2b46eac45960cb5eba603b4f4af27aaa616c81b9c57a2fb552_ppc64le, registry.redhat.io/openshift4/ose-hyperkube-rhel9@sha256:80bee8b97e628b2b46eac45960cb5eba603b4f4af27aaa616c81b9c57a2fb552_ppc64le, * |
| Red Hat | registry.redhat.io/openshift4/ose-csi-snapshot-controller-rhel9@sha256:6dd8ad3c2c3255fd43f2189eea38dab7235a8dab0d2164278859599e5a083f1f_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | * |
| Red Hat | registry.redhat.io/openshift4/ose-prometheus-rhel9-operator@sha256:63cddef49f0c2b8787bbb8f925fbb8a31046c32b22fa3e17c69aa1eb3bbfcdbb_s390x as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-prometheus-rhel9-operator@sha256:63cddef49f0c2b8787bbb8f925fbb8a31046c32b22fa3e17c69aa1eb3bbfcdbb_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:4af03df7bd59f4e234d1d54e053dfc9522a63c787b279f58f528dcb27a8b3040_s390x as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:4af03df7bd59f4e234d1d54e053dfc9522a63c787b279f58f528dcb27a8b3040_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-operator-marketplace-rhel9@sha256:fd8f114964f2ddd50eac3ff9910b9925c16bb19356c1caa9c4ce8398ef8290b2_s390x as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-operator-marketplace-rhel9@sha256:fd8f114964f2ddd50eac3ff9910b9925c16bb19356c1caa9c4ce8398ef8290b2_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-kube-proxy-rhel9@sha256:38befacbe1b568895d82e8b5525af0fcddeb3bb64ac1a0b9c74a04a6ab863eee_s390x as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-kube-proxy-rhel9@sha256:38befacbe1b568895d82e8b5525af0fcddeb3bb64ac1a0b9c74a04a6ab863eee_s390x, registry.redhat.io/openshift4/ose-kube-proxy-rhel9@sha256:38befacbe1b568895d82e8b5525af0fcddeb3bb64ac1a0b9c74a04a6ab863eee_s390x, * |
| Red Hat | registry.redhat.io/openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:902264d7986599efda0954f310743a70e8f7544291252a51b28c99c09dc3ce26_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:902264d7986599efda0954f310743a70e8f7544291252a51b28c99c09dc3ce26_arm64, registry.redhat.io/openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:902264d7986599efda0954f310743a70e8f7544291252a51b28c99c09dc3ce26_arm64, registry.redhat.io/openshift4/ose-multus-whereabouts-ipam-cni-rhel9@sha256:902264d7986599efda0954f310743a70e8f7544291252a51b28c99c09dc3ce26_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:e06854275f16061f05b9f8b82185bf0c7dcc16a2d4fff2b3df10674b54402b0b_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:e06854275f16061f05b9f8b82185bf0c7dcc16a2d4fff2b3df10674b54402b0b_arm64, registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:e06854275f16061f05b9f8b82185bf0c7dcc16a2d4fff2b3df10674b54402b0b_arm64, registry.redhat.io/openshift4/ose-csi-livenessprobe-rhel9@sha256:e06854275f16061f05b9f8b82185bf0c7dcc16a2d4fff2b3df10674b54402b0b_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-kube-state-metrics-rhel9@sha256:c8e4a37847d8c045c1ea77cb360705b7e26e135dbba87cdec1cdb0f8fe331b4f_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-kube-state-metrics-rhel9@sha256:c8e4a37847d8c045c1ea77cb360705b7e26e135dbba87cdec1cdb0f8fe331b4f_amd64, *, registry.redhat.io/openshift4/ose-kube-state-metrics-rhel9@sha256:c8e4a37847d8c045c1ea77cb360705b7e26e135dbba87cdec1cdb0f8fe331b4f_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:10eb26a3677f0e9b6be8e19913806f1fa5aee80ec78a2b9ff5e192502f8bbe57_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:10eb26a3677f0e9b6be8e19913806f1fa5aee80ec78a2b9ff5e192502f8bbe57_ppc64le, registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:10eb26a3677f0e9b6be8e19913806f1fa5aee80ec78a2b9ff5e192502f8bbe57_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-service-ca-rhel9-operator@sha256:0e6cd4a4e896e0a5896e32796832b53bfbd7be266b900a403f493131d89ff02f_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-service-ca-rhel9-operator@sha256:0e6cd4a4e896e0a5896e32796832b53bfbd7be266b900a403f493131d89ff02f_arm64, *, registry.redhat.io/openshift4/ose-service-ca-rhel9-operator@sha256:0e6cd4a4e896e0a5896e32796832b53bfbd7be266b900a403f493131d89ff02f_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:25f8ebb6210e59ddcec9775d28a057011c1b00db408f34276384a19a66616426_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:25f8ebb6210e59ddcec9775d28a057011c1b00db408f34276384a19a66616426_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel9@sha256:eef3db067185cde44051f9bcda8b3800e376b2deb2cb8a655812245cc62ae5c4_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel9@sha256:eef3db067185cde44051f9bcda8b3800e376b2deb2cb8a655812245cc62ae5c4_amd64, registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel9@sha256:eef3db067185cde44051f9bcda8b3800e376b2deb2cb8a655812245cc62ae5c4_amd64, * |
| Red Hat | registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6e83cb5d4d59bc76b34bb0d75e3000abdb936986cee5ed28a63e8a208a51d1bc_s390x as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6e83cb5d4d59bc76b34bb0d75e3000abdb936986cee5ed28a63e8a208a51d1bc_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-container-networking-plugins-rhel9@sha256:5b3a2fd328c44b12fe9b47e2f0a156d6f07547b1d5659561e99545142e384ef7_s390x as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-container-networking-plugins-rhel9@sha256:5b3a2fd328c44b12fe9b47e2f0a156d6f07547b1d5659561e99545142e384ef7_s390x |
| Red Hat | registry.redhat.io/openshift4/network-tools-rhel9@sha256:75ecbb1cf54852205e97cca4ce4b23f46a5ea92871a41e106a4115dacf284487_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/network-tools-rhel9@sha256:75ecbb1cf54852205e97cca4ce4b23f46a5ea92871a41e106a4115dacf284487_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:f09973288fc20799e033ccc92d177a2ca769ff963b95c6a3ae718e760d46ed54_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:f09973288fc20799e033ccc92d177a2ca769ff963b95c6a3ae718e760d46ed54_amd64, registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:f09973288fc20799e033ccc92d177a2ca769ff963b95c6a3ae718e760d46ed54_amd64 |
…and 1314 more
Timeline
- Feb 11, 2026 CVE Published
- May 5, 2026 Distribution Patch
- May 5, 2026 Distribution Patch
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:2119 advisory
- https://access.redhat.com/security/cve/CVE-2025-13465 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2119.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2431740 issue
- https://www.cve.org/CVERecord?id=CVE-2025-13465 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-13465 advisory
- https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory