VYPR
Medium severity5.4OSV Advisory· Published Jul 21, 2021· Updated Jun 17, 2026

CVE-2021-23408

CVE-2021-23408

Description

This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.graphhopper:graphhopper-web-bundleMaven
< 3.23.2

Affected products

5
  • 0.10.0, 0.10.0-RC1, 0.10.alpha1, …+ 3 more
    • (no CPE)range: 0.10.0, 0.10.0-RC1, 0.10.alpha1, …
    • cpe:2.3:a:graphhopper:graphhopper:*:*:*:*:*:*:*:*range: <3.2
    • cpe:2.3:a:graphhopper:graphhopper:4.0:pre1:*:*:*:*:*:*
    • cpe:2.3:a:graphhopper:graphhopper:4.0:pre2:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.