Regular Expression Denial of Service (ReDoS)
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
- Published
- Feb 15, 2021
- Updated
- Oct 8, 2026
- EPSS
- 7.3% · 94th percentile
- CWE
- —
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
23
Monitor
Low priority for now.
- CVSS
- 21 / 40 · 5.3 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 2 / 30 · 7.3%
CISA SSVC decision
- Exploitation
- none
- Automatable
- yes
- Technical impact
- partial
Vulnrichment: CISA's decision-tree inputs.
CNA vs NVD score
- NVD
- 5.3
- CNA · snyk
- 5.3
- agree
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
| Vendor | Product | CPE |
|---|---|---|
| lodash | lodash | cpe:2.3:a:lodash:lodash |
| oracle | banking corporate lending process management | cpe:2.3:a:oracle:banking_corporate_lending_process_management |
| oracle | banking credit facilities process management | cpe:2.3:a:oracle:banking_credit_facilities_process_management |
| oracle | banking extensibility workbench | cpe:2.3:a:oracle:banking_extensibility_workbench |
| oracle | banking supply chain finance | cpe:2.3:a:oracle:banking_supply_chain_finance |
| oracle | banking trade finance process management | cpe:2.3:a:oracle:banking_trade_finance_process_management |
| oracle | communications cloud native core policy | cpe:2.3:a:oracle:communications_cloud_native_core_policy |
| oracle | communications design studio | cpe:2.3:a:oracle:communications_design_studio |
| oracle | communications services gatekeeper | cpe:2.3:a:oracle:communications_services_gatekeeper |
| oracle | communications session border controller | cpe:2.3:a:oracle:communications_session_border_controller |
| oracle | enterprise communications broker | cpe:2.3:a:oracle:enterprise_communications_broker |
| oracle | financial services crime and compliance management studio | cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio |
and 7 more
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- lodash lodashbefore 4.17.21
- oracle banking corporate lending process management14.2.0
- oracle banking corporate lending process management14.3.0
- oracle banking corporate lending process management14.5.0
- oracle banking credit facilities process management14.2.0
- oracle banking credit facilities process management14.3.0
- oracle banking credit facilities process management14.5.0
- oracle banking extensibility workbench14.2.0
- oracle banking extensibility workbench14.3.0
- oracle banking extensibility workbench14.5.0
- oracle banking supply chain finance14.2.0
- oracle banking supply chain finance14.3.0
- oracle banking supply chain finance14.5.0
- oracle banking trade finance process management14.2.0
- oracle banking trade finance process management14.3.0
- oracle banking trade finance process management14.5.0
- oracle communications cloud native core policy1.11.0
- oracle communications design studio7.4.2
- oracle communications services gatekeeper7.0
- oracle communications session border controller8.4
Versions reported by the vendor
Affected version ranges reported by the assigning authority (snyk). Independent of NVD's CPE analysis and usually ahead of it.
n/a Lodash
- versions prior to 4.17.21affected
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| Debian:12 | node-lodash | before 4.17.21+dfsg+~cs8.31.173-1 | 4.17.21+dfsg+~cs8.31.173-1 |
| npm | lodash | from 4.0.0 · before 4.17.21 | 4.17.21 |
| npm | lodash | from 4.0.0 · before 4.17.21 | 4.17.21 |
| npm | lodash-es | from 4.0.0 · before 4.17.21 | 4.17.21 |
| npm | lodash-es | from 4.0.0 · before 4.17.21 | 4.17.21 |
| npm | lodash.trim | from 4.0.0 · up to and including 4.5.1 | — |
| npm | lodash.trim | from 4.0.0 · up to and including 4.5.1 | — |
| npm | lodash.trimend | from 4.0.0 · up to and including 4.5.1 | — |
| npm | lodash.trimend | from 4.0.0 · up to and including 4.5.1 | — |
| Red Hat:rhev_hypervisor:4.4::el8 | cockpit-ovirt | before 0:0.15.1-2.el8ev | 0:0.15.1-2.el8ev |
| Red Hat:rhev_hypervisor:4.4::el8 | cockpit-ovirt-dashboard | before 0:0.15.1-2.el8ev | 0:0.15.1-2.el8ev |
| Red Hat:rhev_manager:4.4:el8 | ovirt-engine-ui-extensions | before 0:1.2.6-1.el8ev | 0:1.2.6-1.el8ev |
| Red Hat:rhev_manager:4.4:el8 | ovirt-web-ui | before 0:1.6.9-1.el8ev | 0:1.6.9-1.el8ev |
| RubyGems | lodash-rails | from 4.0.0 · before 4.17.21 | 4.17.21 |
Same product
lodash: all recordsOther highest-scoring records for the same primary product.
- CVE-2026-4800lodash vulnerable to Code Injection via `_.template` imports key names40Plan
- CVE-2019-10744Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution.38Monitor
- CVE-2021-23337Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.34Monitor
- CVE-2020-8203Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.31Monitor
- CVE-2025-13465Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions28Monitor
- CVE-2019-1010266lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption.27Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| debian:node-lodash | 4.17.21+dfsg+~cs8.31.173-1 · Debian:12 | Package registry (OSV) |
| npm:lodash | 4.17.21 | Package registry (OSV) |
| npm:lodash-es | 4.17.21 | Package registry (OSV) |
| red hat:cockpit-ovirt | 0:0.15.1-2.el8ev · Red Hat:rhev_hypervisor:4.4::el8 | Package registry (OSV) |
| red hat:cockpit-ovirt-dashboard | 0:0.15.1-2.el8ev · Red Hat:rhev_hypervisor:4.4::el8 | Package registry (OSV) |
| red hat:ovirt-engine-ui-extensions | 0:1.2.6-1.el8ev · Red Hat:rhev_manager:4.4:el8 | Package registry (OSV) |
| red hat:ovirt-web-ui | 0:1.6.9-1.el8ev · Red Hat:rhev_manager:4.4:el8 | Package registry (OSV) |
| RubyGems:lodash-rails | 4.17.21 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
National notice (Türkiye Cybersecurity Directorate / USOM)
Official security notices citing this record; remediation advice is on the agency's page.
- TR-21-0701 · Sep 3, 2021(IBM Güvenlik Bülteni Yayınladı)
- TR-21-0500 · Jun 21, 2021(IBM Güvenlik Bülteni Yayınladı)
- TR-21-0387 · May 6, 2021(IBM Güvenlik Bülteni Yayınladı)
Technical details
Attack conditions
- Anyone who can reach it over the internet can trigger it.
- No account or password is required.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- none
- Integrity
- none
- Availability
- low · the service can be disrupted
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- Low
Weakness class (CWE)
—
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- SSVC exploitation— → none
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- github.com/lodash/lodash/blob/npm/trimEnd.js%23L8
- github.com/lodash/lodash/pull/5065
- security.netapp.com/advisory/ntap-20210312-0006/
- www.oracle.com//security-alerts/cpujul2021.html
- www.oracle.com/security-alerts/cpujan2022.html
- www.oracle.com/security-alerts/cpujul2022.html
- www.oracle.com/security-alerts/cpuoct2021.html
Vendor advisories and official records. Exploit/PoC links are deliberately left out.