Skip to content

CVE-2026-4800 CVE-2026-2950 lodash vulnerable to Code Injection via _.template imports key names lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit#978

Merged
vharseko merged 2 commits into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/lodash-4.18.1
Apr 2, 2026
Merged

CVE-2026-4800 CVE-2026-2950 lodash vulnerable to Code Injection via _.template imports key names lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit#978
vharseko merged 2 commits into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/lodash-4.18.1

Bump lodash from 4.17.23 to 4.18.1 in /openam-ui/openam-ui-api (#979)

384b71a
Select commit
Loading
Failed to load commit list.
Sign in for the full log view

Annotations

1 warning
build-maven (11, ubuntu-latest)
succeeded Apr 2, 2026 in 48m 18s