Prototype Pollution is a vulnerability tracked across 12 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed November 7, 2025; most recent activity June 29, 2026.
Multiple vulnerabilities in Lodash were discovered, affecting several Ubuntu LTS versions including 16.04, 18.04, 20.04, 22.04, 24.04, and 25.10. The vulnerabilities include a prototype pollution issue in the…
On June 5, 2026, Fedora released updates for NextCloud addressing two critical vulnerabilities: CVE-2026-42044 and CVE-2026-44167. CVE-2026-42044 involves JSON response tampering via prototype pollution in Axios, while…
A critical vulnerability in Dottie affects Ubuntu 22.04 LTS and 20.04 LTS, allowing remote code execution via specially crafted network traffic. Discovered by Yuhan Gao and Peng Zhou, the issue stems from prototype…
Fedora has released updates for the nodejs package to address a prototype pollution vulnerability in the js-yaml library, identified as CVE-2025-64718. This vulnerability affects multiple Fedora versions, specifically…
Fedora 43 has released a fix for a moderate prototype pollution vulnerability identified as CVE-2025-13465 affecting pgAdmin4, a popular open-source administration tool for PostgreSQL. The vulnerability was published on…
Fedora has released updates for yarnpkg to address a critical prototype pollution vulnerability identified as CVE-2025-13465, which was published on January 21, 2026. The updates include regenerating the vendor tarball…
CVE-2025-13465 was published on January 21, 2026, affecting the openQA and os-autoinst testing frameworks used in Fedora 43. These frameworks are essential for automating tests of operating system components and…
A critical vulnerability in Axios, tracked as CVE-2026-40175, was reported with a CVSS score of 9.9, suggesting potential for remote code execution (RCE) and cloud infrastructure compromise. However, analysis reveals…
The PCPcat malware campaign has compromised more than 59,000 servers in under 48 hours by exploiting critical vulnerabilities in .js and React frameworks. It specifically targets vulnerabilities CVE-2025-29927 and…
A critical vulnerability has been identified in the expr-eval JavaScript library, which has over 800,000 weekly downloads on NPM. This vulnerability, tracked as CVE-2025-12735, allows for remote code execution through…