{"id":"CVE-2026-48714","title":"i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names","summary":"i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names","severity":"critical","cvss":9.1,"cwe":["CWE-1321"],"vendor":"i18next-http-middleware","product":"i18next-http-middleware","ecosystem":"npm","affected":["i18next-http-middleware < 3.9.7"],"patched":["i18next-http-middleware 3.9.7"],"published":"2026-06-25","updated":"2026-06-25","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-f49m-vf83-692w","references":[{"url":"https://github.com/i18next/i18next-http-middleware/security/advisories/GHSA-f49m-vf83-692w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48714"},{"url":"https://github.com/i18next/i18next-http-middleware/commit/7c6d26f137d3e940b8d229ca148bca38845faf49"},{"url":"https://github.com/advisories/GHSA-f49m-vf83-692w"}],"tags":["ghsa","npm"],"epss":0.00507,"epssPercentile":0.42273,"ingestedAt":"2026-06-26T16:43:14.246Z","slug":"CVE-2026-48714","body":"## Overview\n\n### Impact\n\n`i18next-http-middleware` ≤ 3.9.6's `missingKeyHandler` blocked the literal request-body keys `__proto__`, `constructor`, and `prototype` (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as `\"__proto__.polluted\"`. Downstream backends that split the missing-key string on a configured `keySeparator` (notably `i18next-fs-backend` ≤ 2.6.5) hand these keys to an unguarded `setPath()` walker that writes to `Object.prototype`.\n\nApplications that expose `missingKeyHandler` to untrusted input **AND** use `i18next-fs-backend` ≤ 2.6.5 are directly exploitable for remote prototype pollution. Other downstream backends that split the missing-key string the same way may be similarly affected.\n\nDepending on the host application, polluted prototype properties may cause crashes, corrupted translation behaviour, configuration poisoning, or bypasses of property-based security checks.\n\n### Patches\n\nFixed in **i18next-http-middleware 3.9.7**. A new `utils.hasUnsafeKeySegment(key, keySeparator)` helper is now used by `missingKeyHandler`; the configured `i18next.options.keySeparator` is honoured (default `.`; `false` disables segment splitting and only the literal-key denylist applies). Legitimate dotted keys (e.g. `\"header.title\"`) are unaffected.\n\nThe root-cause fix has been shipped in `i18next-fs-backend` **2.6.6** — see the companion advisory.\n\n### Workarounds\n\nIf users cannot upgrade immediately:\n\n- Do not expose `missingKeyHandler` to untrusted users (mount it behind authentication, or remove the route).\n- Add a request-body filter ahead of the handler that rejects any top-level key containing `__proto__`, `constructor`, or `prototype` after splitting on a configured `keySeparator`.\n- Disable missing-key persistence (`saveMissing: false`) when accepting writes from untrusted input.\n\n### Resources\n\n- Original report by [@codeswhite](https://github.com/codeswhite).\n- Companion advisory in `i18next-fs-backend`: [GHSA-2933-q333-qg83](https://github.com/i18next/i18next-fs-backend/security/advisories/GHSA-2933-q333-qg83).\n- Previous `i18next-http-middleware` security release: GHSA-5fgg-jcpf-8jjw and GHSA-c3h8-g69v-pjrg (in 3.9.3).\n\n## Affected packages\n\n- `i18next-http-middleware < 3.9.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `i18next-http-middleware 3.9.7`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}