CVE 8.6 HIGH

Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters_CVE-2026-41690

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Description

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal object-key writes: getResourcesHandler and missingKeyHandler. This can break authorisation checks (if (user.isAdmin) returning true for any user), cause type-confusion DoS, and depending on downstream code it can be chained into RCE.

AI Analysis

Prototype pollution and path traversal vulnerability in i18next-http-middleware via user-controlled language and namespace parameters

Basic Information

ID CVE-2026-41690
Source GitHub_M
Published May 8, 2026 at 15:24

Affected Product

Vendor i18next
Product i18next-http-middleware
Version < 3.9.3
Affected Versions i18next i18next-http-middleware < 3.9.3

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor i18next
Product i18next-http-middleware
Version < 3.9.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.