Lodash version 4.17.21 is affected by CVE-2025-13465 Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions
37945
28 July 2026
28 July 2026
CLOSED
MEDIUM
6.9 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P
CVE-2025-13465
|
Brocade Security Advisory ID |
BSA-2026-3503 |
|
Component |
Lodash |
|
|
|
Summary
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
Products Affected
- Brocade SANnav 3.0.0
Products Not Affected
- Brocade SANNav before 3.0.0 is Not Exploitable. Only hard-coded values are used.: [VEX Justification: Inline_mitigations_already_exist]
- Brocade Fabric OS is not exploitable. Only hard-coded values are used.: [VEX Justification: Inline_mitigations_already_exist]
- Brocade ASCG is not affected. Vex status code:[VEX Justification: Component_not_present]
Solution
- Security update provided in Brocade SANnav 3.0.1 and 3.0.0a
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
July 28th, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.