Object Prototype Pollution in i18next-http-middleware for Node.js
CVE-2026-41690

8.6HIGH

Key Information:

Vendor

I18next

Vendor
CVE Published:
8 May 2026

What is CVE-2026-41690?

The i18next-http-middleware for Node.js allows unauthenticated HTTP clients to exploit specific unvalidated entry points, namely getResourcesHandler and missingKeyHandler. This flaw can lead to pollution of the Object.prototype, potentially disrupting authorization checks and creating type-confusion denial of service (DoS) vulnerabilities. Additionally, given certain downstream code scenarios, this vulnerability may even facilitate remote code execution (RCE), posing a serious security risk to applications utilizing the middleware. It is advisable for users to upgrade to version 3.9.3 or later to mitigate this risk.

Affected Version(s)

i18next-http-middleware < 3.9.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.