CVE-2026-41690Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal object-key writes: getResourcesHandler and missingKeyHandler. This can break authorisation checks (if (user.isAdmin) returning true for any user), cause type-confusion DoS, and depending on downstream code it can be chained into RCE.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-08: 2Technical Details · 2026-05-08: 205-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41690 Prototype Pollution in i18next-http-middleware Before 3.9.3 Enables Unauthenticated Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41690

    Post summary

    The post highlights that i18next-http-middleware versions below 3.9.3 suffer from prototype‑pollution leading to potential unauthenticated attacks, but provides no evidence of active exploitation or a PoC, and does not mention fixes.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41690 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthentica… https://www.cve.org/CVERecord?id=CVE-2026-41690

    Post summary

    The text presents a disclosure of CVE‑2026‑41690, noting vulnerable 18next‑http‑middleware versions before 3.9.3, without providing PoC, exploit, or mitigation details.

    0000075
    57.5K followersView on X

Explore more