CVE Vulnerabilities

CVE-2025-13465

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Jan 21, 2026 | Modified: Jun 02, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.

The issue permits deletion of properties but does not allow overwriting their original behavior.

This issue is patched on 4.17.23

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

NameVendorStart VersionEnd Version
LodashLodash4.0.0 (including)4.17.23 (excluding)
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-openshift-console-plugin-rhel9:4.1.0-17*
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-rhel9:4.1.0-17*
HawtIO HawtIO 4.4.0RedHatio.hawt-project*
Red Hat Ansible Automation Platform 2.6 for RHEL 9RedHatautomation-platform-ui-0:2.6.6-1.el9ap*
Red Hat Data Grid 8.6.0RedHatorg.infinispan-infinispan-console*
Red Hat Enterprise Linux 10RedHatpcs-0:0.12.1-1.el10_1.2*
Red Hat Enterprise Linux 10RedHatlinux-sgx-0:2.26-7.el10*
Red Hat Enterprise Linux 10RedHatcockpit-image-builder-0:94.3-1.el10_2*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatpcs-0:0.12.0-3.el10_0.4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpcs-0:0.10.8-1.el8_4.10*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatpcs-0:0.10.8-1.el8_4.10*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpcs-0:0.10.12-6.el8_6.12*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpcs-0:0.10.12-6.el8_6.12*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpcs-0:0.10.15-4.el8_8.10*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpcs-0:0.10.15-4.el8_8.10*
Red Hat Enterprise Linux 9RedHatlinux-sgx-0:2.26-7.el9*
Red Hat Enterprise Linux 9RedHatpcs-0:0.11.10-1.el9_7.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatpcs-0:0.11.1-10.el9_0.10*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatpcs-0:0.11.4-7.el9_2.7*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpcs-0:0.11.7-2.el9_4.6*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpcs-0:0.11.9-2.el9_6.3*
Cluster Observability Operator 1.4.0RedHatcluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1773337158*
Cluster Observability Operator 1.4.0RedHatcluster-observability-operator/monitoring-console-plugin-rhel9:1773337078*
Multicluster engine for Kubernetes 2.10RedHatmulticluster-engine/console-mce-rhel9:1777128790*
Multicluster engine for Kubernetes 2.6RedHatmulticluster-engine/console-mce-rhel9:1776223790*
Multicluster engine for Kubernetes 2.7RedHatmulticluster-engine/console-mce-rhel9:1773100128*
Multicluster engine for Kubernetes 2.8RedHatmulticluster-engine/console-mce-rhel9:1775116156*
Multicluster engine for Kubernetes 2.9RedHatmulticluster-engine/console-mce-rhel9:1777301444*
Network Observability (NETOBSERV) 1.11.2RedHatnetwork-observability/network-observability-console-plugin-compat-rhel9:1771227610*
Network Observability (NETOBSERV) 1.11.2RedHatnetwork-observability/network-observability-console-plugin-rhel9:1771227650*
Red Hat Advanced Cluster Management for Kubernetes 2.12RedHatrhacm2/console-rhel9:1773259174*
Red Hat Advanced Cluster Management for Kubernetes 2.13RedHatrhacm2/console-rhel9:1775116130*
Red Hat Advanced Cluster Management for Kubernetes 2.15RedHatrhacm2/console-rhel9:1776927126*
Red Hat Advanced Cluster Security for Kubernetes 4.10RedHatadvanced-cluster-security/rhacs-main-rhel8:1777976489*
Red Hat Advanced Cluster Security for Kubernetes 4.8RedHatadvanced-cluster-security/rhacs-main-rhel8:1773235880*
Red Hat Advanced Cluster Security for Kubernetes 4.9RedHatadvanced-cluster-security/rhacs-main-rhel8:1773235860*
Red Hat Ansible Automation Platform 2.5RedHatansible-automation-platform-25/lightspeed-rhel8:1772214630*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/gateway-rhel9:1772543959*
Red Hat Ansible Automation Platform 2.6RedHatansible-automation-platform-26/lightspeed-rhel9:1772552788*
Red Hat Developer Hub 1.8RedHatrhdh/rhdh-hub-rhel9:1770656494*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1770913709*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-dashboard-rhel9:1772093424*
Red Hat OpenShift AI 2.25RedHatrhoai/odh-mod-arch-model-registry-rhel9:1772093498*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-dashboard-rhel9:1779189627*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-mod-arch-gen-ai-rhel9:1778473763*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-mod-arch-model-registry-rhel9:1778666987*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4/ose-console:1772633840*
Red Hat OpenShift Container Platform 4.13RedHatopenshift4/ose-console:1771854568*
Red Hat OpenShift Container Platform 4.14RedHatopenshift4/ose-monitoring-plugin-rhel8:1778036641*
Red Hat OpenShift Container Platform 4.14RedHatopenshift4/ose-console:1771425150*
Red Hat OpenShift Container Platform 4.15RedHatopenshift4/ose-monitoring-plugin-rhel8:1777994844*
Red Hat OpenShift Container Platform 4.15RedHatopenshift4/ose-console:1773067104*
Red Hat OpenShift Container Platform 4.16RedHatopenshift4/ose-monitoring-plugin-rhel9:1779262817*
Red Hat OpenShift Container Platform 4.16RedHatopenshift4/ose-console-rhel9:1770831186*
Red Hat OpenShift Container Platform 4.17RedHatopenshift4/ose-console-rhel9:1770775465*
Red Hat OpenShift Container Platform 4.18RedHatopenshift4/ose-console-rhel9:1770235261*
Red Hat OpenShift Container Platform 4.18RedHatopenshift4/nmstate-console-plugin-rhel9:1779874967*
Red Hat OpenShift Container Platform 4.19RedHatopenshift4/nmstate-console-plugin-rhel9:1779249920*
Red Hat OpenShift Container Platform 4.19RedHatopenshift4/ose-console-rhel9:1770665886*
Red Hat OpenShift Container Platform 4.20RedHatopenshift4/nmstate-console-plugin-rhel9:1778645008*
Red Hat OpenShift Container Platform 4.20RedHatopenshift4/ose-console-rhel9:1769816382*
Red Hat OpenShift Container Platform 4.21RedHatopenshift4/ose-monitoring-plugin-rhel9:1771393951*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/code-rhel9:1774448966*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/dashboard-rhel9:1774476526*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/openvsx-rhel9:1773775064*
Red Hat OpenShift Dev Spaces 3.27RedHatdevspaces/traefik-rhel9:1774227265*
Red Hat OpenShift GitOps 1.17RedHatopenshift-gitops-1/console-plugin-rhel8:1772195995*
Red Hat OpenShift GitOps 1.18RedHatopenshift-gitops-1/argocd-rhel9:1772439154*
Red Hat OpenShift GitOps 1.18RedHatopenshift-gitops-1/console-plugin-rhel8:1772438822*
Red Hat OpenShift GitOps 1.19RedHatopenshift-gitops-1/console-plugin-rhel8:1772447156*
Red Hat OpenShift Pipelines 1.15RedHatopenshift-pipelines/pipelines-console-plugin-rhel8:1772110573*
Red Hat OpenShift Pipelines 1.15RedHatopenshift-pipelines/pipelines-console-plugin-rhel8:1772110573*
Red Hat OpenShift Pipelines 1.2RedHatopenshift-pipelines/pipelines-console-plugin-rhel9:1770988020*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-ossmc-rhel8:1770140426*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-rhel8:1770140470*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1770140791*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-rhel9:1770140853*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1770140180*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-rhel9:1770138727*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-ossmc-rhel9:1770142326*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-rhel9:1770138513*
Red Hat Quay 3.16RedHatquay/quay-rhel9:1775069491*
Red Hat Quay 3.16RedHatquay/quay-rhel9:1775169226*
Red Hat Satellite 6.18RedHatsatellite/iop-advisor-frontend-rhel9:1777911535*
Red Hat Satellite 6.18RedHatsatellite/iop-host-inventory-frontend-rhel9:1777498806*
Red Hat Satellite 6.18RedHatsatellite/iop-remediations-rhel9:1773242477*
Red Hat Trusted Artifact Signer 1.2RedHatrhtas/rekor-search-ui-rhel9:1770739056*
Red Hat Trusted Artifact Signer 1.3RedHatrhtas/rhtas-console-ui-rhel9:1771324807*
Node-lodashUbuntuesm-apps-legacy/xenial*
Node-lodashUbuntuesm-apps/bionic*
Node-lodashUbuntuesm-apps/focal*
Node-lodashUbuntuesm-apps/jammy*
Node-lodashUbuntuesm-apps/noble*
Node-lodashUbuntuesm-apps/xenial*
Node-lodashUbuntujammy*
Node-lodashUbuntunoble*
Node-lodashUbuntuquesting*
Node-lodashUbuntuupstream*

Potential Mitigations

References