CVE-2026-4800
Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.3 Security Update
Description
A flaw was found in lodash. The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Metrics
Weakness classes (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4800.json">CVE-2026-4800</a>
- CVE Modified2026-09-09 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4800.json">CVE-2026-4800</a>
- CVE Modified2026-09-07 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4800.json">CVE-2026-4800</a>
- CVE Modified2026-09-03 13:05 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4800.json">CVE-2026-4800</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:59833
- CVE Modified2026-08-31 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4800.json">CVE-2026-4800</a>
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
golang1.25.0
bitnami
golang1.25.0-0
bitnami
golang1.26.0-0
golang
crypto0.52.0
golang
go1.26.0 – 1.26.2
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
go1.25.8
golang
go1.25.9
golang
go
golang
net0.55.0
grpc
grpc1.79.3
immutable-js
immutable3.0.0 – 3.8.3
immutable-js
immutable4.0.0 – 4.3.7
immutable-js
immutable5.0.0 – 5.1.5
jackc
pgx5.9.0
lodash
lodash4.0.0 – 4.17.23
lodash
lodash4.0.0 – 4.18.0
lodash
lodash-amd4.0.0 – 4.18.0
lodash
lodash-es4.0.0 – 4.18.0
lodash
lodash.template4.0.0 – 4.18.0
openjsf
fast-uri2.3.1 – 3.1.3
openjsf
fast-uri4.0.0 – 4.0.1
openjsf
fast-uri3.1.2
References & sources
- https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6web
- https://nvd.nist.gov/vuln/detail/CVE-2026-13676advisory
- https://github.com/fastify/fast-uri/pull/188web
- https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05web
- https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bdweb
- https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1dweb
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.jsonweb
- https://github.com/fastify/fast-uri/releases/tag/v4.0.1web
- https://github.com/fastify/fast-uri/releases/tag/v3.1.3web
- https://github.com/fastify/fast-uri/releases/tag/v2.4.2web
- https://github.com/fastify/fast-uripackage
- https://cna.openjsf.org/security-advisories.htmlweb
- https://bugzilla.redhat.com/show_bug.cgi?id=2494197web
- https://access.redhat.com/security/cve/CVE-2026-13676web
- https://access.redhat.com/errata/RHSA-2026:48126web
- https://access.redhat.com/errata/RHSA-2026:48124web
- https://access.redhat.com/errata/RHSA-2026:44268web
- https://access.redhat.com/errata/RHSA-2026:44239web
- https://access.redhat.com/errata/RHSA-2026:43038web
- https://access.redhat.com/errata/RHSA-2026:42815web
Linked CVEs
- CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-4926
A flaw was found in path-to-regexp.
highCVSSv3 7.5 - CVE-2026-46595
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 10.0 - CVE-2026-42508
A flaw was found in golang.org/x/crypto/ssh/knownhosts.
criticalCVSSv3 9.1 - CVE-2026-42154
A flaw was found in Prometheus.
highCVSSv3 7.5 - CVE-2026-42151
A flaw was found in Prometheus, an open-source monitoring system.
highCVSSv3 7.5 - CVE-2026-39835
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 5.3 - CVE-2026-39832
A flaw was found in golang.org/x/crypto/ssh/agent.
criticalCVSSv3 9.1 - CVE-2026-39830
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 9.1 - CVE-2026-39829
A flaw was found in golang.org/x/crypto/ssh.
highCVSSv3 7.5 - CVE-2026-39828
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 6.3 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-33816
A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go.
criticalCVSSv3 9.8 - CVE-2026-33811
A flaw was found in the `net` package of Go (golang), specifically when using the `LookupCNAME` function with the `cgo` DNS resolver.
highCVSSv3 7.5 - CVE-2026-33810
A flaw was found in the `crypto/x509` package within Go (golang).
highCVSSv3 8.2 - CVE-2026-33186
A flaw was found in gRPC-Go, the Go language implementation of gRPC.
criticalCVSSv3 9.1 - CVE-2026-32282
A flaw was found in the internal/syscall/unix package in the Go standard library.
mediumCVSSv3 6.4 - CVE-2026-32281
A flaw was found in Go's `crypto/x509` package.
highCVSSv3 7.5 - CVE-2026-32280
A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`.
highCVSSv3 7.5 - CVE-2026-32141
A denial of service flaw has been discovered in the flatted npm library.
highCVSSv3 7.5 - CVE-2026-29063
A flaw was found in Immutable.js, a library for persistent immutable data structures.
criticalCVSSv3 9.8 - CVE-2026-25679
The Go standard library function net/url.Parse insufficiently validated the host/authority component and accepted some invalid URLs by ef…
highCVSSv3 7.5 - CVE-2026-22029
A cross site scripting flaw has been discovered in the npm react-router and @remix-run/router packages.
highCVSSv3 8.0 - CVE-2026-13676
A flaw was found in fast-uri.
highCVSSv3 7.5