Red Hat Security Advisory: RHACS 4.9.4 security and bug fix update
See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.
AI Analysis
Technical Summary
CVE-2025-13465 is a prototype pollution vulnerability in lodash's _.unset and _.omit functions. An attacker able to control the property path argument can delete properties from global prototypes, leading to denial of service by removing critical functionality. The vulnerability does not allow overwriting behavior, limiting impact to denial of service only. It affects applications that use these lodash functions on objects with user input determining the property path. Red Hat's affected products include Red Hat OpenShift Container Platform 4.20 and others that bundle the vulnerable lodash version. Red Hat Enterprise Linux 8.10 and later are not affected as they no longer include the vulnerable lodash component in PCS. The vulnerability has been rated with important severity by Red Hat, with a CVSS base score of 8.2 by cve.org but availability impact is considered high only by Red Hat due to denial of service potential. Mitigation requires strict input validation to block prototype chain access strings such as __proto__, constructor, and prototype.
Potential Impact
The vulnerability allows denial of service by deleting methods from global prototypes via prototype pollution. This can cause loss of functionality or crashes in affected applications. There is no confidentiality or integrity impact. The issue is exploitable only if user input controls the property path passed to _.unset or _.omit. Red Hat rates the severity as important/high due to denial of service impact. Red Hat Enterprise Linux 8.10 and later are not affected as the vulnerable lodash component is not included in PCS. The impact is limited to denial of service, not arbitrary code execution or data disclosure.
Mitigation Recommendations
Red Hat has issued security advisories and updates addressing this vulnerability in affected products. To mitigate, implement strict input validation to block user input that attempts to access prototype chain properties such as __proto__, constructor, and prototype before passing property paths to _.unset and _.omit functions. Red Hat Enterprise Linux 8.10 and later are not affected. Users should apply the official Red Hat updates for their affected products as provided in the Red Hat security advisories. No additional action is required if running unaffected versions or products without the vulnerable lodash component.
Red Hat Security Advisory: RHACS 4.9.4 security and bug fix update
Description
See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-13465 is a prototype pollution vulnerability in lodash's _.unset and _.omit functions. An attacker able to control the property path argument can delete properties from global prototypes, leading to denial of service by removing critical functionality. The vulnerability does not allow overwriting behavior, limiting impact to denial of service only. It affects applications that use these lodash functions on objects with user input determining the property path. Red Hat's affected products include Red Hat OpenShift Container Platform 4.20 and others that bundle the vulnerable lodash version. Red Hat Enterprise Linux 8.10 and later are not affected as they no longer include the vulnerable lodash component in PCS. The vulnerability has been rated with important severity by Red Hat, with a CVSS base score of 8.2 by cve.org but availability impact is considered high only by Red Hat due to denial of service potential. Mitigation requires strict input validation to block prototype chain access strings such as __proto__, constructor, and prototype.
Potential Impact
The vulnerability allows denial of service by deleting methods from global prototypes via prototype pollution. This can cause loss of functionality or crashes in affected applications. There is no confidentiality or integrity impact. The issue is exploitable only if user input controls the property path passed to _.unset or _.omit. Red Hat rates the severity as important/high due to denial of service impact. Red Hat Enterprise Linux 8.10 and later are not affected as the vulnerable lodash component is not included in PCS. The impact is limited to denial of service, not arbitrary code execution or data disclosure.
Mitigation Recommendations
Red Hat has issued security advisories and updates addressing this vulnerability in affected products. To mitigate, implement strict input validation to block user input that attempts to access prototype chain properties such as __proto__, constructor, and prototype before passing property paths to _.unset and _.omit functions. Red Hat Enterprise Linux 8.10 and later are not affected. Users should apply the official Red Hat updates for their affected products as provided in the Red Hat security advisories. No additional action is required if running unaffected versions or products without the vulnerable lodash component.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:13829
- Cve Count
- 8
- Additional Cves
- ["CVE-2026-29063","CVE-2026-32282","CVE-2026-33186","CVE-2026-33815","CVE-2026-33816","CVE-2026-34986","CVE-2026-35469"]
Threat ID: 6a160955e29bf47b5061a79f
Added to database: 05/26/2026, 20:57:57 UTC
Last enriched: 08/15/2026, 00:09:21 UTC
Last updated: 09/15/2026, 01:45:37 UTC
Views: 276
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.