CVE-2023-26136: Salesforce Tough-Cookie

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.

Affected products

  • Salesforce Tough-Cookie: before 4.1.3 (fixed in 4.1.3)

Published 2023-07-01. Last modified 2026-06-17.