Home/Product/lodash
Product

lodash

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-4800
>= 4.0.0 and < 4.18.0
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option i
8.1HIGH
CVE-2026-2950
>= 4.0.0 and < 4.17.23
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix fo
6.5MEDIUM
CVE-2025-13465
>= 4.0.0 and < 4.17.23
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can
5.3MEDIUM
CVE-2021-23337
< 4.17.21
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
7.2HIGH
CVE-2020-28500
< 4.17.21
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd
5.3MEDIUM
CVE-2020-8203
< 4.17.20
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
7.4HIGH
CVE-2019-10744
< 4.17.12
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into addin
9.1CRITICAL
CVE-2019-1010266
< 4.17.11
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The componen
6.5MEDIUM
CVE-2018-16487
< 4.17.11
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tri
5.6MEDIUM
CVE-2018-3721
< 4.17.5
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merg
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin