Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-27601

Medium priority
Needs evaluation

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in...

1 affected package

ruby-rails-assets-underscore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-assets-underscore Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-23358

Medium priority
Fixed

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is...

1 affected package

underscore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
underscore Fixed Fixed
Show less packages