Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2026-73649
- EPSS 0.5%
- Veröffentlicht 13.08.2026 18:18:20
- Zuletzt bearbeitet 14.08.2026 17:20:35
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while prop...
9.8
CVE-2026-44966
- EPSS 0.51%
- Veröffentlicht 26.05.2026 21:21:29
- Zuletzt bearbeitet 24.07.2026 12:10:00
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity template...
1