CVE-2026-48714Disclor(i18next / i18next-http-middleware)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "__proto__.polluted". Downstream backends that split the missing-key string on a configured keySeparator (notably i18next-fs-backend ≤ 2.6.5) hand these keys to an unguarded setPath() walker that writes to Object.prototype. Applications that expose missingKeyHandler to untrusted input AND use i18next-fs-backend ≤ 2.6.5 are directly exploitable for remote prototype pollution. Other downstream backends that split the missing-key string the same way may be similarly affected. Depending on the host application, polluted prototype properties may cause crashes, corrupted translation behaviour, configuration poisoning, or bypasses of property-based security checks. This issue has been fixed in version 3.9.7. If developers cannot upgrade immediately, they should do the following: do not expose missingKeyHandler to untrusted users (mount it behind authentication, or remove the route), add a request-body filter ahead of the handler that rejects any top-level key containing __proto__, constructor, or prototype after splitting on their configured keySeparator, and disable missing-key persistence (saveMissing: false) when accepting writes from untrusted input.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i18next-http-middleware

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclor: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
i18next-http-middleware

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-16: 1Mentions · 2026-06-25: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-25: 106-1606-25
Signal classification2 categories
Disclor
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-161
Disclor1
2026-06-251
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 i18next-http-middleware Prototype Pollution via missingKeyHandler (#CVE-2026-48714) – Critical -DC-Jun2026-631 https://dailycve.com/i18next-http-middleware-prototype-pollution-via-missingkeyhandler-cve-2026-48714-critical-dc-jun2026-631/

    Post summary

    A critical prototype pollution vulnerability (CVE‑2026‑48714) has been disclosed for i18next-http-middleware, but no PoC, exploit details, or patch information is provided.

    0000048
    216 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclor

    CVE-2026-48714 Prototype Pollution in i18next-http-middleware Versions Prior to 3.9.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48714

    Post summary

    A new prototype‑pollution vulnerability (CVE‑2026‑48714) affecting i18next‑http‑middleware before v3.9.7 has been disclosed, but no PoC, exploit, active exploitation, patch or mitigation details are provided.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appi18nexti18next-http-middleware-node.js-

Explore more