Shepherdwind

Velocity.Js

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 13.08.2026 18:18:20
  • Zuletzt bearbeitet 14.08.2026 17:20:35

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while prop...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 26.05.2026 21:21:29
  • Zuletzt bearbeitet 24.07.2026 12:10:00

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity template...