CVE-2026-8657Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of Object.prototype.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-16); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-16: 3Mentions · 2026-05-17: 2Patch / Workaround · 2026-05-16: 2Technical Details · 2026-05-16: 3Technical Details · 2026-05-17: 205-1605-17
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-163
Disclosure3
2026-05-172
Disclosure1General1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Prototype Pollution Vulnerability CVE-2026-8657 affects jsondiffpatch versions prior to 0.7.6. Attackers can exploit unsafe patch-handling APIs to perform Prototype Pollution, potentially modifying the Object prototype. prototype and affecting application behavior throughout the entire Node.js process. Affected APIs include: • jsondiffpatch.patch() • jsondiffpatch/formatters/jsonpatch.patch() 🔧 Recommendation: Upgrade to jsondiffpatch 0.7.6+ immediately and review applications processing untrusted JSON Patch input.

    Post summary

    CVE-2026-8657 is a high‑severity prototype pollution vulnerability in jsondiffpatch versions before 0.7.6, and users are advised to immediately upgrade to 0.7.6 or later to mitigate the risk.

    0002092
    196 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8657 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() AP… https://www.cve.org/CVERecord?id=CVE-2026-8657 ----- Traducción: CVE-2026-8657 Las… http://infoflow.cloud`

    Post summary

    The message announces that jsondiffpatch versions prior to 0.7.6 are vulnerable to prototype pollution via specific API calls.

    0000042
    78 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8657 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() AP… https://www.cve.org/CVERecord?id=CVE-2026-8657

    Post summary

    The text merely announces CVE-2026-8657 for jsondiffpatch versions <0.7.6, noting a prototype‑pollution flaw, but offers no exploit, remediation, or evidence of active attacks.

    00000363
    57.5K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚨 CVE-2026-8657: jsondiffpatch before 0.7.6 is vulnerable to prototype pollution through patch APIs. Crafted delta or JSON Patch input can let an attacker modify object prototypes and potentially lead to broader impact in apps that trust this library. Update immediately. #JavaScript #CVE #AppSec

    Post summary

    The post announces a prototype pollution flaw in jsondiffpatch (CVE‑2026‑8657) and urges users to apply the latest update.

    0000011
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8657 Prototype Pollution in jsondiffpatch Before 0.7.6 via Patc... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8657 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-8657, identifying a Prototype Pollution flaw in jsondiffpatch before v0.7.6, but provides no PoC, exploit, or remediation details.

    0000087
    4.0K followersView on X

Explore more