CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
539 vulnerabilities with CWE-1321
CVE-2026-46509
HIGH
deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 8.2
CVE-2026-44483
HIGH
RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFormData (HTTP form data)
CVSS 8.2
CVE-2026-44966
HIGH
Velocity.js: Prototype Pollution in #set path assignment
CVSS 8.3
CVE-2026-9101
MEDIUM
MongoDB Compass - Prototype Pollution via CSV Import Leading to Command Execution
CVSS 4.3
CVE-2026-8657
HIGH
Jsondiffpatch < 0.7.6 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 8.2
CVE-2026-44005
CRITICAL
vm2: Sandbox escape
CVSS 10.0
CVE-2026-44292
MEDIUM
protobufjs: Prototype injection in generated message constructors
CVSS 5.3
CVE-2026-44290
HIGH
protobufjs: Process-wide denial of service through unsafe option paths
CVSS 7.5
CVE-2026-8161
HIGH
multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
CVSS 7.5
CVE-2026-41690
HIGH
Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters
CVSS 8.6
CVE-2026-42264
HIGH
Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
CVSS 7.4
CVE-2026-42232
HIGH
n8n: XML Node Prototype Pollution to RCE
CVSS 8.8
CVE-2026-42231
HIGH
n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE
CVSS 8.8
CVE-2026-42077
MEDIUM
Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations
CVSS 5.2
CVE-2026-42044
MEDIUM
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVSS 6.5
CVE-2026-42041
MEDIUM
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
CVSS 4.8
CVE-2026-42035
HIGH
Axios: Header Injection via Prototype Pollution
CVSS 7.4
CVE-2026-42033
HIGH
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
CVSS 7.4
CVE-2026-41238
MEDIUM
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
CVSS 6.9
CVE-2026-6621
HIGH
1024bit extend-deep index.js prototype pollution
CVSS 7.3
CVE-2026-6594
HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-34626
MEDIUM
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 6.3
CVE-2026-34622
HIGH
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 8.6
CVE-2026-34621
HIGH
KEV
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVSS 8.6
CVE-2026-40190
MEDIUM
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
CVSS 5.6
Details
Vulnerabilities
539