Multiple Lodash Vulnerabilities Affecting Ubuntu Versions

Multiple Lodash Vulnerabilities Affecting Ubuntu Versions

First seen 9 Jun 2026, 20:20 UTC UbuntuLinuxsecurity 87% similarity 72.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities in Lodash were discovered, affecting several Ubuntu LTS versions including 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. The vulnerabilities include a prototype pollution issue in the zipObjectDeep function (CVE-2020-8203), a denial of service issue in the toNumber, trim, and trimEnd functions (CVE-2020-28500), and improper input sanitization in the template function (CVE-2021-23337). An attacker could exploit these vulnerabilities to modify application behavior, consume excessive system resources, or execute arbitrary commands. The issues were confirmed by various researchers and are critical for users of the affected Ubuntu versions. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities have been patched in the latest package versions available through Ubuntu Pro.

Key Points: • Lodash vulnerabilities affect multiple Ubuntu LTS versions, including 16.04 to 26.04. • Critical issues include prototype pollution and denial of service vulnerabilities. • Users are urged to update their systems to the latest patched versions.

ThreatCluster AI

Timeline

2020-07-15
CVE-2020-8203 published
Prototype pollution vulnerability in Lodash's zipObjectDeep function was disclosed, affecting Ubuntu 18.04 and 20.04.
Ubuntu
2021-02-15
CVE-2020-28500 published
Denial of service vulnerability in Lodash's toNumber, trim, and trimEnd functions was disclosed, affecting Ubuntu 18.04 and 20.04.
Ubuntu
2021-02-15
CVE-2021-23337 published
Improper input sanitization vulnerability in Lodash's template function was disclosed, affecting Ubuntu 16.04, 18.04, and 20.04.
Ubuntu
2026-01-21
CVE-2025-13465 published
New prototype pollution vulnerability in Lodash was disclosed, affecting Ubuntu 16.04 to 26.04.
Linuxsecurity
2026-03-31
CVE-2026-4800 and CVE-2026-2950 published
New vulnerabilities in Lodash were disclosed, affecting multiple Ubuntu versions.
Linuxsecurity
2026-06-09
Security notice released
Ubuntu issued USN-8411-1, detailing multiple Lodash vulnerabilities and urging users to update.
Ubuntu

Community

Browse all →

Tracked Entities in This Story