Object Prototype Pollution in i18next-http-middleware for Node.js
CVE-2026-41690
8.6HIGH
What is CVE-2026-41690?
The i18next-http-middleware for Node.js allows unauthenticated HTTP clients to exploit specific unvalidated entry points, namely getResourcesHandler and missingKeyHandler. This flaw can lead to pollution of the Object.prototype, potentially disrupting authorization checks and creating type-confusion denial of service (DoS) vulnerabilities. Additionally, given certain downstream code scenarios, this vulnerability may even facilitate remote code execution (RCE), posing a serious security risk to applications utilizing the middleware. It is advisable for users to upgrade to version 3.9.3 or later to mitigate this risk.
Affected Version(s)
i18next-http-middleware < 3.9.3
