Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31114 | dref is vulnerable to prototype pollution |
Github GHSA |
GHSA-76g8-235f-gj6p | dref is vulnerable to prototype pollution |
Thu, 25 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1321 | |
| Metrics |
cvssV3_1
|
Thu, 25 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-25T18:50:56.541Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26278
Updated: 2025-09-25T18:50:50.620Z
Status : Deferred
Published: 2025-09-25T14:15:43.873
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-26278
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA