CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2021-23337, CVE-2025-13465, CVE-2026-2950 +1 more CVEs: Affected product not specified by the source

CVE-2021-23337, CVE-2025-13465, CVE-2026-2950, CVE-2026-4800 affects lodash. EPSS 0.21333 (percentile 0.97539), scored 2026-10-05. Fixed version: 4.17.23-tuxcare.1.

CVE-2021-23337

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2025-13465

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as low; integrity impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-2950

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

CVE-2026-4800

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CVE
CVE-2026-4800
Product
lodash
CCR priority
5.3 /100 (P5)
EPSS
0.21333 · percentile 0.97539 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-23337.html