{"id":"USN-8411-1","summary":"node-lodash vulnerabilities","details":"It was discovered that Lodash was vulnerable to a prototype pollution\nissue in the zipObjectDeep function. An attacker could possibly use this\nissue to modify application behavior. This issue only affected Ubuntu\n18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8203)\n\nLiyuan Chen discovered that Lodash was vulnerable to a regular\nexpression denial of service issue in the toNumber, trim, and trimEnd\nfunctions. An attacker could possibly use this issue to consume\nexcessive system resources, resulting in a denial of service. This issue\nonly affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-28500)\n\nMarc Hassan discovered that Lodash did not properly sanitize input to\nthe template function. An attacker could possibly use this issue to\ninject and execute arbitrary commands. This issue only affected Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-23337)\n\nIt was discovered that Lodash was vulnerable to a prototype pollution\nissue in the unset and omit functions. An attacker could possibly use\nthis issue to delete properties from global prototypes, resulting in\nsecurity restrictions being bypassed. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 25.10. (CVE-2025-13465)\n\nIt was discovered that Lodash was vulnerable to a prototype pollution\nissue in the unset and omit functions. An attacker could possibly use\nthis issue to delete properties from built-in prototypes, resulting in\nsecurity restrictions being bypassed. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu\n25.10, and Ubuntu 26.04 LTS. (CVE-2026-2950)\n\nIt was discovered that Lodash did not properly validate certain inputs\nto the template function. An attacker could possibly use this issue to\ninject malicious code during template processing, resulting in arbitrary\ncode execution. (CVE-2026-4800)","modified":"2026-06-09T21:29:22.699680278Z","published":"2026-06-09T15:16:59Z","related":["UBUNTU-CVE-2020-28500","UBUNTU-CVE-2020-8203","UBUNTU-CVE-2021-23337","UBUNTU-CVE-2025-13465","UBUNTU-CVE-2026-2950","UBUNTU-CVE-2026-4800"],"upstream":["CVE-2020-28500","CVE-2020-8203","CVE-2021-23337","CVE-2025-13465","CVE-2026-2950","CVE-2026-4800","UBUNTU-CVE-2020-28500","UBUNTU-CVE-2020-8203","UBUNTU-CVE-2021-23337","UBUNTU-CVE-2025-13465","UBUNTU-CVE-2026-2950","UBUNTU-CVE-2026-4800"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8411-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-8203"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-28500"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-23337"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-13465"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-2950"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-4800"}],"affected":[{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1+dfsg-3ubuntu0.1~esm1"}]}],"versions":["2.4.1+dfsg-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"2.4.1+dfsg-3ubuntu0.1~esm1"},{"binary_name":"node-lodash","binary_version":"2.4.1+dfsg-3ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-23337"},{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.4+dfsg-1ubuntu0.1~esm1"}]}],"versions":["4.17.4+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.4+dfsg-1ubuntu0.1~esm1"},{"binary_name":"node-lodash","binary_version":"4.17.4+dfsg-1ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-8203"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-28500"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-23337"},{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.15+dfsg-2ubuntu0.1~esm1"}]}],"versions":["4.17.11+dfsg-4","4.17.15+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.15+dfsg-2ubuntu0.1~esm1"},{"binary_name":"node-lodash","binary_version":"4.17.15+dfsg-2ubuntu0.1~esm1"},{"binary_name":"node-lodash-packages","binary_version":"4.17.15+dfsg-2ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-8203"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-28500"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2021-23337"},{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1"}]}],"versions":["4.17.21+dfsg+~cs8.31.173-1","4.17.21+dfsg+~cs8.31.196.20210220-2","4.17.21+dfsg+~cs8.31.198.20210220-4","4.17.21+dfsg+~cs8.31.198.20210220-5"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1"},{"binary_name":"node-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1"},{"binary_name":"node-lodash-packages","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-9"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1"},{"binary_name":"node-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1"},{"binary_name":"node-lodash-packages","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-9"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1"},{"binary_name":"node-lodash","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1"},{"binary_name":"node-lodash-packages","binary_version":"4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-13465"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:25.10"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}},{"package":{"name":"node-lodash","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/node-lodash?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.23+dfsg-1ubuntu0.1~esm1"}]}],"versions":["4.17.21+dfsg+~cs8.31.198.20210220-9","4.17.23+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-lodash","binary_version":"4.17.23+dfsg-1ubuntu0.1~esm1"},{"binary_name":"node-lodash","binary_version":"4.17.23+dfsg-1ubuntu0.1~esm1"},{"binary_name":"node-lodash-packages","binary_version":"4.17.23+dfsg-1ubuntu0.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-2950"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-4800"}],"ecosystem":"Ubuntu:Pro:26.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8411-1.json"}}],"schema_version":"1.7.5"}