Linuxsecurity Multiple Lodash Vulnerabilities Affecting Ubuntu Versions
Article Content
- •Lodash vulnerabilities affect multiple Ubuntu LTS versions, including 16.04 to 26.04.
- •Critical issues include prototype pollution and denial of service vulnerabilities.
- •Users are urged to update their systems to the latest patched versions.
Multiple vulnerabilities in Lodash were discovered, affecting several Ubuntu LTS versions including 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. The vulnerabilities include a prototype pollution issue in the zipObjectDeep function (CVE-2020-8203), a denial of service issue in the toNumber, trim, and trimEnd functions (CVE-2020-28500), and improper input sanitization in the template function (CVE-2021-23337). An attacker could exploit these vulnerabilities to modify application behavior, consume excessive system resources, or execute arbitrary commands. The issues were confirmed by various researchers and are critical for users of the affected Ubuntu versions. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities have been patched in the latest package versions available through Ubuntu Pro.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2020-28500 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Vulnerabilities in Axios Affecting Ubuntu 26.04 LTS A series of vulnerabilities in Axios, a promise-based HTTP client, were discovered, affecting Ubuntu 26.04 LTS. Key issues include improper handling of NO_PROXY rules, which could allow attackers to bypass proxy restrictions and access internal services, leading to server-side request forgery (CVE-2025-62718…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…