Bug 2453499 (CVE-2026-2950)

Summary: CVE-2026-2950 lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aadhikar, aazores, abarbaro, abokovoy, abrianik, abuckta, akostadi, alcohan, alizardo, amasferr, amctagga, anjoseph, anpicker, anthomas, anujha, aoconnor, aschwart, asoldano, aszczucz, bbaranow, bbrownin, bdettelb, bmaxwell, bniver, boliveir, bparees, brasmith, bsmejkal, bstansbe, caswilli, cdrage, chfoley, cmah, cmyers, cochase, dbosanac, dhanak, dkeler, dkuc, dlofthou, dmayorov, dnakabaa, doconnor, dranck, drichtar, drosa, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, erezende, ewittman, fdeutsch, flucifre, frenaud, ftrivino, ggainey, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibek, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jbalunas, jchui, jfula, jgrulich, jhe, jhorak, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jraez, jreimann, jrokos, juwatts, jwong, kaycoth, kbempah, kshier, ktsao, lball, lchilton, lcouzens, lphiri, manissin, mbarnett, mbenjamin, mdessi, mhackett, mhulan, mnovotny, mosmerov, mposolda, mreynolds, mrizzi, mstipich, msvehla, mvyas, mwringe, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, progier, prwatson, psrna, ptisnovs, rchan, rekumar, rexwhite, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sausingh, sdawley, sdoran, sfeifer, simaishi, slucidi, smaestri, smallamp, smcdonal, smullick, snegrini, solenoci, sostapov, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, stirabos, suppawar, swoodman, syedriko, tasato, tbordaz, teagle, thason, thjenkin, tmalecek, tpopela, tsedmik, ttakamiy, vashirov, vdosoudi, vereddy, veshanka, vmuzikar, vvoronko, watson-tool-maintainers, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Lodash. An attacker can exploit a prototype pollution vulnerability in the `_.unset` and `_.omit` functions by bypassing a security check. This bypass is achieved by providing array-wrapped path segments, which allows for the deletion of properties from built-in JavaScript prototypes such as `Object.prototype`. This could lead to unexpected application behavior or denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-03-31 20:02:02 UTC
Impact:

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.

The issue permits deletion of prototype properties but does not allow overwriting their original behavior.

Patches:

This issue is patched in 4.18.0.

Workarounds:

None. Upgrade to the patched version.