Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
Prototype Pollution
Vulnerability
Threat entity extracted from intelligence sources
Entities
›
vulnerability
›
Prototype Pollution
Frequency
18
occurrences
First Seen
November 7, 2025
Last Seen
August 13, 2026
API
Overview
Recent Events
Profile
Profile
1 / 1
Associated Malware
PCPcat
React2Shell
Tools Used
JavaScript
Node.js
Npm
Related CVEs
CVE-2025-13465
CVE-2026-42044
CVE-2026-40175
CVE-2026-42043
CVE-2026-44167
CVE-2025-62718
CVE-2026-2950
CVE-2026-42264
Affected Platforms
Axios
Nextcloud
Yarnpkg
Express
Linux
PgAdmin4
Related Clusters (13)
Multiple Lodash Vulnerabilities Affecting Ubuntu Versions
Jun 9
·
2 sources
73
Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities
Jun 5
·
2 sources
72
Multiple Vulnerabilities in Axios Affecting Ubuntu 26.04 LTS
Aug 13
·
2 sources
71
Critical Remote Code Execution Vulnerability in Ubuntu Dottie
Feb 12
·
2 sources
62
Fedora Updates Address js-yaml Prototype Pollution Vulnerability
Mar 17
·
2 sources
58
Fedora 43 pgAdmin4 Fixes Moderate Prototype Pollution Vulnerability CVE-2025-13465
Feb 5
·
6 sources
57
Critical Prototype Pollution Fix for yarnpkg in Fedora
Feb 6
·
2 sources
48
Critical CVE-2025 Affects Fedora 43 openQA and os-autoinst
Feb 4
·
3 sources
47
Axios CVE-2026-40175: Critical Vulnerability Misrepresented as Easily Exploitable
Apr 14
·
6 sources
43
PCPcat Malware Compromises Over 59,000 Servers via React2Shell Exploit
Dec 15
·
2 sources
42
Critical Vulnerability Discovered in expr-eval JavaScript Library
Nov 10
·
2 sources
41
Snyk VulnBench JS 1.0 Reveals Inconsistencies in LLM Security Findings
Jun 29
·
2 sources
40
Critical Vulnerability Discovered in expr-eval JavaScript Library
Nov 10
·
2 sources
28
Prev
1 / 3
Next
Related Articles (18)
Ubuntu 26.04 LTS Axios High Server-Side Request Forgery Issues USN-8638
Linuxsecurity
·
Aug 13
USN-8638-1: Axios vulnerabilities
Ubuntu
·
Aug 13
Snyk VulnBench JS 1.0: LLM Bug Repeatability
Snyk
·
Jun 29
Snyk VulnBench JS 1.0: LLM Bug Repeatability
Snyk
·
Jun 29
Ubuntu 26.04 LTS Lodash Critical Prototype Pollution Vuln USN-8411
Linuxsecurity
·
Jun 9
Fedora 44 NextCloud Update Denial of Service JSON Tampering 2026
Linuxsecurity
·
Jun 5
Fedora 43 nextcloud 33.0.4 Critical JSON Tampering DoS CVE-2026
Linuxsecurity
·
Jun 5
CC-4770
Digital.Nhs.Uk
·
Apr 14
Fedora 42 nodejs Package Update Includes Patch for js
Linuxsecurity
·
Mar 17
Ubuntu 22.04 Dottie Critical Remote Code Execution USN-8041
Linuxsecurity
·
Feb 12
USN-8041-1: Dottie vulnerability
Ubuntu
·
Feb 12
Fedora 42 yarnpkg Critical Prototype Pollution Fix FEDORA-2026
Linuxsecurity
·
Feb 6
Fedora 42 pgAdmin 4 CVE-2025
Linuxsecurity
·
Feb 6
Fedora 43 yarnpkg Advisory 2026-a75abb3f2b CVE-2025
Linuxsecurity
·
Feb 5
Fedora 43 pgAdmin4 Moderate Prototype Pollution Fix CVE-2025
Linuxsecurity
·
Feb 5
Fedora 43 os-autoinst Update CVE-2025
Linuxsecurity
·
Feb 4
New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers
Cybersecuritynews
·
Dec 15
VU#263614: Vulnerability in expr
Kb.Cert
·
Nov 7
Prev
1 / 4
Next
Related Entities
HTTP Header Injection
Denial of Service
Remote Code Execution
Server-Side Request Forgery
Sql Injection
Zero-day Exploit
Code Injection
Command Injection
DDoS
Malware
Fedora
Ubuntu