Description
Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf).
Recommendation
Update the ts-deepmerge package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.0.0
- Patched version(s): 8.0.0
References
Related Issues
- axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions - CVE-2026-44490
- Qwik City has array method pollution in FormData processing allows type confusion and DoS - CVE-2026-32701
- xmldom: Uncontrolled recursion in XML serialization leads to DoS - xmldom - CVE-2026-41673
- xmldom: Uncontrolled recursion in XML serialization leads to DoS - CVE-2026-41673
You might also like:
- Tags:
- npm
- ts-deepmerge
Anything's wrong? Let us know Last updated on June 19, 2026


