Critical severity9.8OSV Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-28271
CVE-2020-28271
Description
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
deephasnpm | >= 1.0.0, <= 1.0.5 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/sharpred/deepHas/commit/2fe011713a6178c50f7deb6f039a8e5435981e20nvdPatchThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28271nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4fr2-j4g9-mppfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28271ghsaADVISORY
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28271,ghsaWEB
News mentions
0No linked articles in our index yet.