Vulnerabilities/

Redoc Prototype Pollution via `Module.mergeObjects` Component

Severity:
High

Description

A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Recommendation

Update the redoc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
redoc
Anything's wrong? Let us know Last updated on March 31, 2025

This issue is available in SmartScanner Professional

See Pricing