CVE-2019-1010266: Lodash
Medium severity, CVSS 6.5. EPSS: 3.2% chance of exploitation in the next 30 days.
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.
Affected products
- Lodash Lodash: before 4.17.11 (fixed in 4.17.11)
Published 2019-07-17. Last modified 2026-06-17.