CVE-2026-44966Disclosure(shepherdwind / velocity.js)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE) depending on the server environment.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • velocity.js

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
velocity.js

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 105-0905-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Velocity.js Prototype Pollution (CVE-2026-44966) A prototype pollution vulnerability in Velocity.js exists within the processing of #set directives. By providing crafted template content, an attacker can modify Object.prototype via sensitive keys like __proto__. This can lead to application crashes (DoS) or be chained to achieve Remote Code Execution (RCE). 👉 Affected: velocityjs <= 2.1.5

    Post summary

    Velocity.js is impacted by CVE-2026-44966, a prototype pollution flaw that can be escalated to remote code execution or cause denial‑of‑service in versions ≤2.1.5.

    00030102
    255 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Velocityjs, Prototype Pollution, #CVE-2026-44966 (High) https://dailycve.com/velocityjs-prototype-pollution-cve-2026-44966-high/

    Post summary

    The text announces the CVE-2026-44966 vulnerability in Velocityjs as a high‑severity prototype pollution issue, but it does not provide PoC details, exploit mechanisms, patches, or evidence of active exploitation.

    0000050
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshepherdwindvelocity.js-node.js-

Explore more