CVE-2026-33228
WebReflection flatted, Cluster Observability Operator 1.5.0, Red Hat Developer Hub 1.8 취약점
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property...
- 대응 우선순위
- 점검
- CVSS
- 8.9
- EPSS
- 0.81% 백분위 53.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.03.21