CVE-2026-33228
WebReflection flatted, Cluster Observability Operator 1.5.0, Red Hat Developer Hub 1.8
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property...
- CVSS
- 8.9
- EPSS
- 0.81% 53.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.21