VYPR

jsondiffpatch

by Jsondiffpatch

CVEs (1)

  • CVE-2026-8657HigMay 16, 2026
    risk 0.46cvss 8.2epss 0.00

    Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as…