CVE-2026-5758

ADVISORY - github

Summary

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.

Common Weakness Enumeration (CWE)

ADVISORY - nist
ADVISORY - github

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

ADVISORY - redhat

Improperly Controlled Modification of Dynamically-Determined Object Attributes


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in