CVE Vulnerabilities

CVE-2025-13465

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Jan 21, 2026 | Modified: Feb 17, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.

The issue permits deletion of properties but does not allow overwriting their original behavior.

This issue is patched on 4.17.23

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

NameVendorStart VersionEnd Version
LodashLodash4.0.0 (including)4.17.23 (excluding)
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-openshift-console-plugin-rhel9:4.1.0-17*
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-rhel9:4.1.0-17*
Red Hat Enterprise Linux 10RedHatpcs-0:0.12.1-1.el10_1.2*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatpcs-0:0.12.0-3.el10_0.4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpcs-0:0.10.8-1.el8_4.10*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatpcs-0:0.10.8-1.el8_4.10*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpcs-0:0.10.12-6.el8_6.12*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpcs-0:0.10.12-6.el8_6.12*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpcs-0:0.10.15-4.el8_8.10*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpcs-0:0.10.15-4.el8_8.10*
Red Hat Enterprise Linux 9RedHatpcs-0:0.11.10-1.el9_7.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatpcs-0:0.11.1-10.el9_0.10*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatpcs-0:0.11.4-7.el9_2.7*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpcs-0:0.11.7-2.el9_4.6*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpcs-0:0.11.9-2.el9_6.3*
Network Observability (NETOBSERV) 1.11.0RedHatnetwork-observability/network-observability-console-plugin-compat-rhel9:sha256:325db5ee476d5467e24748b6a66def44ff06e91e7e0665f43a49d7df9dbc9870*
Network Observability (NETOBSERV) 1.11.0RedHatnetwork-observability/network-observability-console-plugin-rhel9:sha256:3f4b1539a41af46e0dcc3ee1e06d760b504448190cf1f5963171e504cbcb82e2*
Red Hat Developer Hub 1.8RedHatrhdh/rhdh-hub-rhel9:sha256:114b288483eccad70b18159c9f75de9c061bdf9ee269198a75c3efeb68a43a2b*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:2ff9787699ff67dab7ee6f300d84651233f499aac8aeee10bfe21381806393c4*
Red Hat OpenShift Container Platform 4.14RedHatopenshift4/ose-console:sha256:39af4cee0a425da0814b28bdd6d515a397544d3c5f83b5e9cfffb7aa33c4fbb5*
Red Hat OpenShift Container Platform 4.16RedHatopenshift4/ose-console-rhel9:sha256:2996e3821813cad87e4bbef83d22bab2bdb80ade147e2f827714321a06d50769*
Red Hat OpenShift Container Platform 4.17RedHatopenshift4/ose-console-rhel9:sha256:80793968484982ba2d52eabd86548f294b096923a432049a73b39cf51e31b889*
Red Hat OpenShift Container Platform 4.18RedHatopenshift4/ose-console-rhel9:sha256:6a7462a57f3b25a5fc080fbe5daa50e2a5ee09b80b1f3015abc184ee079fd550*
Red Hat OpenShift Container Platform 4.19RedHatopenshift4/ose-console-rhel9:sha256:f4a65b5386d74b203f29b8fbff069211fc756bdade1ecbdaffdb64a289bad2a7*
Red Hat OpenShift Container Platform 4.2RedHatopenshift4/ose-console-rhel9:sha256:422f8d8700c8be8f4a532894a4c62fb1a4affbd29b8772097a5e790bb528656e*
Red Hat OpenShift Container Platform 4.21RedHatopenshift4/ose-monitoring-plugin-rhel9:sha256:b0f7fd94fa47603540b7c49967aa1921d5c1c063576f6ecee524a52400bd1089*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-ossmc-rhel8:sha256:4e910b08863756516707f2ad8198c04dc6d706c78f481561a3b2e896800d4dbe*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-rhel8:sha256:ad1449f9047107c23d5b0e53c3ca148a12a9729dd7aa474c5eadb55870f314fa*
Red Hat OpenShift Service Mesh 3RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:19c44dfb277123122abafc25552fe408ea7ad6dc026aa592f53e3a754ca0a44f*
Red Hat OpenShift Service Mesh 3RedHatopenshift-service-mesh/kiali-rhel9:sha256:527fd434b3b1f9b9304adbedd89a593ca347a84571a68c7935afe6aa207db49f*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:e5a71ca768b96c827dd2fd860cbd739d7743f1eeb89b2e4c7cc9157941683626*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-rhel9:sha256:a60d01bfe3bfa2dc484f9d940b71538f0b3732cb77db883edb7a93cf42f2992e*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:fcb5d2c8e4ae372cb0009dc15d46eb5a10163139b61b063115c3d3fce90265e1*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-rhel9:sha256:ef18675f445508d01ae56ef59709b70d4b69187bb03425061cac62998f643fe5*
Red Hat Trusted Artifact Signer 1.2RedHatrhtas/rekor-search-ui-rhel9:sha256:1e3a46ade52215e2c78df9229f36301c94099e8397ee74ab99fb8bd504ce7aa2*
Red Hat Trusted Artifact Signer 1.3RedHatrhtas/rhtas-console-ui-rhel9:sha256:e7ee88dd498d337304db3d90f4f352e55114475dbc9d75c3b18a49a249492b1e*

Potential Mitigations

References