CVE-2023-26136: Salesforce Tough-Cookie
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Affected products
- Salesforce Tough-Cookie: before 4.1.3 (fixed in 4.1.3)
Published 2023-07-01. Last modified 2026-06-17.