---
id: CVE-2026-33228
title: flatted is a circular JSON parser
summary: >-
  flatted is a circular JSON parser. Prior to version 3.4.2, the parse()
  function in flatted can use attacker-controlled string values from the parsed
  JSON as direct array index keys, without validating that they are numeric.
  Since the int…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1321
  - CWE-915
published: '2026-03-20'
updated: '2026-06-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33228'
references:
  - url: >-
      https://github.com/WebReflection/flatted/commit/885ddcc33cf9657caf38c57c7be45ae1c5272802
    label: security-advisories@github.com
  - url: 'https://github.com/WebReflection/flatted/releases/tag/v3.4.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/WebReflection/flatted/security/advisories/GHSA-rf6f-7fwh-wjgh
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:13826'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9742'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-33228'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2449872'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33228.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00989
epssPercentile: 0.60878
ingestedAt: '2026-06-29T13:24:34.809Z'
---

## Overview

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live reference to Array.prototype to the consumer. Any code that subsequently writes to that property will pollute the global prototype. This issue has been patched in version 3.4.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
