Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90771

Опубликовано: 13 сент. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

A flaw was found in joi. This vulnerability, known as prototype pollution, exists in the messages compilation function. A remote attacker can exploit this by supplying specially crafted __proto__ keys in custom messages. This allows the attacker to manipulate object properties, which could lead to unexpected application behavior or crashes.

Отчет

A flaw in joi permits prototype manipulation when attacker-controlled JSON or configuration containing proto is supplied to the .messages() or .prefs() APIs, potentially disrupting downstream application behavior.

Меры по смягчению последствий

Upgrade joi to 17.13.8, 18.2.9, or later. Avoid passing untrusted data to Joi message configuration until upgraded.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Red Hat Build of Podman Desktoprh-podman-desktop.gitFix deferred
Red Hat Data Grid 8redhat-datagrid-maven-repository.zipFix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 8grafana-pcpFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred
Red Hat Hardened Imagesgrafana12.4Affected
Red Hat Hardened Imagesgrafana13.1Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2532688joi: joi: Prototype Pollution via custom messages

EPSS

Процентиль: 18%
0.00258
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
7 дней назад

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

CVSS3: 3.7
github
7 дней назад

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

EPSS

Процентиль: 18%
0.00258
Низкий

5.9 Medium

CVSS3