CVE-2026-27601HIGHCVSS 8.2fixed in 1.13.82026-03-03
CVE-2026-27601 [HIGH] CWE-770 CVE-2026-27601: Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastr
cvelistv5nvd