CVE-2021-26707

CRITICAL

Merge-deep < 3.0.3 - Prototype Pollution

Title source: rule
STIX 2.1

Description

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

References (4)

Core 4
Core References
Product, Third Party Advisory x_refsource_misc
https://www.npmjs.com/package/merge-deep
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210716-0008/

Scores

CVSS v3 9.8
EPSS 0.0109
EPSS Percentile 78.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (3)
merge-deep_project/merge-deep < 3.0.3
netapp/e-series_performance_analyzer
npm/merge-deep 0 - 3.0.3npm
Published Jun 02, 2021
Tracked Since Feb 18, 2026