CVE-2019-10746: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Affected products

  • Fedoraproject Fedora: version 30 only; version 31 only
  • Mixin-Deep Project Mixin-Deep: before 1.3.2 (fixed in 1.3.2); version 2.0.0 only
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.4.0 only

Published 2019-08-23. Last modified 2026-06-17.