CVE Vulnerabilities

CVE-2025-58280

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Sep 05, 2025 | Modified: Sep 11, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

Name Vendor Start Version End Version
Harmonyos Huawei 5.0.1 (including) 5.0.1 (including)
Harmonyos Huawei 5.1.0 (including) 5.1.0 (including)

Potential Mitigations

References