Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-87mf-gv2c-c62c | ts-deepmerge: Prototype Method Override leads to DoS |
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voodoocreation
Voodoocreation ts-deepmerge |
|
| Vendors & Products |
Voodoocreation
Voodoocreation ts-deepmerge |
Mon, 22 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Uncaught Exception in ts-deepmerge from Improper Handling of Object.prototype Methods |
Fri, 19 Jun 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context operation throws a TypeError, crashing the application. | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-06-22T15:03:43.502Z
Reserved: 2026-06-18T18:00:17.870Z
Link: CVE-2026-12644
Updated: 2026-06-22T15:03:01.118Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:41:54Z
Github GHSA