VYPR
Medium severity6.5NVD Advisory· Published Jul 17, 2019· Updated Jun 17, 2026

CVE-2019-1010266

CVE-2019-1010266

Description

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
lodashnpm
>= 4.7.0, < 4.17.114.17.11
lodash-esnpm
>= 4.7.0, < 4.17.114.17.11
lodash-amdnpm
>= 4.7.0, < 4.17.114.17.11
lodash-railsRubyGems
>= 4.7.0, < 4.17.114.17.11

Affected products

6
  • Lodash/Lodashv52 versions
    <4.17.11 [fixed: 4.7.11]+ 1 more
    • (no CPE)range: <4.17.11 [fixed: 4.7.11]
    • cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*range: <4.17.11
  • ghsa-coords4 versions
    >= 4.7.0, < 4.17.11+ 3 more
    • (no CPE)range: >= 4.7.0, < 4.17.11
    • (no CPE)range: >= 4.7.0, < 4.17.11
    • (no CPE)range: >= 4.7.0, < 4.17.11
    • (no CPE)range: >= 4.7.0, < 4.17.11

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.