Skip to content
Multiple Lodash Vulnerabilities Affecting Ubuntu Versions

Multiple Lodash Vulnerabilities Affecting Ubuntu Versions

First seen 9 Jun 2026, 20:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 20:17 UTC
  • Lodash vulnerabilities affect multiple Ubuntu LTS versions, including 16.04 to 26.04.
  • Critical issues include prototype pollution and denial of service vulnerabilities.
  • Users are urged to update their systems to the latest patched versions.

Multiple vulnerabilities in Lodash were discovered, affecting several Ubuntu LTS versions including 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. The vulnerabilities include a prototype pollution issue in the zipObjectDeep function (CVE-2020-8203), a denial of service issue in the toNumber, trim, and trimEnd functions (CVE-2020-28500), and improper input sanitization in the template function (CVE-2021-23337). An attacker could exploit these vulnerabilities to modify application behavior, consume excessive system resources, or execute arbitrary commands. The issues were confirmed by various researchers and are critical for users of the affected Ubuntu versions. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities have been patched in the latest package versions available through Ubuntu Pro.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2020-07-15
CVE-2020-8203 published
Prototype pollution vulnerability in Lodash's zipObjectDeep function was disclosed, affecting Ubuntu 18.04 and 20.04.
Ubuntu
2021-02-15
CVE-2020-28500 published
Denial of service vulnerability in Lodash's toNumber, trim, and trimEnd functions was disclosed, affecting Ubuntu 18.04 and 20.04.
Ubuntu
2021-02-15
CVE-2021-23337 published
Improper input sanitization vulnerability in Lodash's template function was disclosed, affecting Ubuntu 16.04, 18.04, and 20.04.
Ubuntu
2026-01-21
CVE-2025-13465 published
New prototype pollution vulnerability in Lodash was disclosed, affecting Ubuntu 16.04 to 26.04.
Linuxsecurity
2026-03-31
CVE-2026-4800 and CVE-2026-2950 published
New vulnerabilities in Lodash were disclosed, affecting multiple Ubuntu versions.
Linuxsecurity
2026-06-09
Security notice released
Ubuntu issued USN-8411-1, detailing multiple Lodash vulnerabilities and urging users to update.
Ubuntu

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2020-28500 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed