Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLSA-2026-1785468076
  • TuxCare:npm/lodash-es
TuxCare security update for lodash-es (7 CVEs) 04 Aug
  • Fix available
CLSA-2026-1785468081
  • TuxCare:npm/lodash-es
TuxCare security update for lodash-es (3 CVEs) 04 Aug
  • Fix available
CLSA-2026-1785468082
  • TuxCare:npm/lodash-es
TuxCare security update for lodash-es (6 CVEs) 04 Aug
  • Fix available
ROOT-APP-NPM-CVE-2021-23337
  • Root:npm/@rootio/lodash
  • Root:npm/@rootio/lodash-es
  • Root:npm/@rootio/lodash.template
  • Root:npm/lodash
  • Root:npm/lodash-es
  • ... 1 more
CVE-2021-23337 in @rootio/lodash.template - Patched by Root 16 Jul
  • Fix available
  • Severity - 7.2 (High)
ROOT-APP-NPM-CVE-2026-4800
  • Root:npm/@rootio/lodash
  • Root:npm/@rootio/lodash-es
  • Root:npm/@rootio/lodash.template
  • Root:npm/lodash
  • Root:npm/lodash-es
  • ... 1 more
CVE-2026-4800 in @rootio/lodash - Patched by Root 16 Jul
  • Fix available
  • Severity - 8.1 (High)
ROOT-APP-NPM-CVE-2025-13465
  • Root:npm/@rootio/lodash
  • Root:npm/@rootio/lodash-es
  • Root:npm/lodash
  • Root:npm/lodash-es
CVE-2025-13465 in @rootio/lodash - Patched by Root 04 Jun
  • Fix available
  • Severity - 6.5 (Medium)
ROOT-APP-NPM-CVE-2026-2950
  • Root:npm/@rootio/lodash
  • Root:npm/@rootio/lodash-es
  • Root:npm/lodash
  • Root:npm/lodash-es
CVE-2026-2950 in @rootio/lodash - Patched by Root 04 Jun
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-r5fr-rjxr-66jc
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.template
lodash vulnerable to Code Injection via `_.template` imports key names 01 Apr
  • Fix available
  • Severity - 8.1 (High)
GHSA-f23m-r3pf-42rh
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.unset
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` 01 Apr
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-xxjr-mmjv-4gpg
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.unset
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions 21 Jan
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-29mw-wpgm-hmr9
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-es
  • npm/lodash.trim
  • npm/lodash.trimend
Regular Expression Denial of Service (ReDoS) in lodash 06 Jan 2022
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-35jh-r3h4-6jhm
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-es
  • npm/lodash-template
  • npm/lodash.template
Command Injection in lodash 06 May 2021
  • Fix available
  • Severity - 7.2 (High)
GHSA-p6mc-m468-83gw
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-es
  • npm/lodash.pick
  • npm/lodash.set
  • ... 3 more
Prototype Pollution in lodash 15 Jul 2020
  • Fix available
  • Severity - 7.4 (High)
GHSA-x5rq-j2xg-h7qm
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
Regular Expression Denial of Service (ReDoS) in lodash 19 Jul 2019
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-jf85-cpcp-j695
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.defaultsdeep
Prototype Pollution in lodash 10 Jul 2019
  • Fix available
  • Severity - 9.1 (Critical)