CVE-2020-28500Medium· 5.3▾ SunlitLodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.3%
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
lodash < 4.17.21banking_corporate_lending_process_management = 14.2.0banking_corporate_lending_process_management = 14.3.0banking_corporate_lending_process_management = 14.5.0banking_credit_facilities_process_management = 14.2.0banking_credit_facilities_process_management = 14.3.0banking_credit_facilities_process_management = 14.5.0banking_extensibility_workbench = 14.2.0banking_extensibility_workbench = 14.3.0banking_extensibility_workbench = 14.5.0banking_supply_chain_finance = 14.2.0banking_supply_chain_finance = 14.3.0banking_supply_chain_finance = 14.5.0banking_trade_finance_process_management = 14.2.0banking_trade_finance_process_management = 14.3.0banking_trade_finance_process_management = 14.5.0communications_cloud_native_core_policy = 1.11.0communications_design_studio = 7.4.2communications_services_gatekeeper = 7.0communications_session_border_controller = 8.4communications_session_border_controller = 9.0enterprise_communications_broker = 3.2.0enterprise_communications_broker = 3.3.0financial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0health_sciences_data_management_workbench = 2.5.2.1health_sciences_data_management_workbench = 3.0.0.0jd_edwards_enterpriseone_tools < 9.2.6.1peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59primavera_gateway >= 17.12.0, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.12primavera_gateway >= 19.12.0, <= 19.12.11primavera_gateway >= 20.12.0, <= 20.12.7primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12retail_customer_management_and_segmentation_foundation = 19.0sinec_ins < 1.0sinec_ins = 1.0Upgrade past the affected range:
lodash 4.17.21jd_edwards_enterpriseone_tools 9.2.6.1sinec_ins 1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-23337High· 7.2Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVE-2026-4800High· 8.1Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names
CVE-2025-13465Medium· 5.3Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions