← Vulnerability feed

Vulnerability record · CVE-2020-28500 · published 15 February 2021

CVE-2020-28500: Lodash vulnerability

Lodash · Lodash

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

5.3 CVSS 3.1 Medium EPSS 7.3% · top 5.8%
5.3CVSS 3.1 base score, v2 5.0
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
19Affected product versions listed by NVD
28References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf PatchThird Party Advisory
https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8 Broken Link
https://github.com/lodash/lodash/pull/5065 PatchThird Party Advisory
https://security.netapp.com/advisory/ntap-20210312-0006/ Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JS-LODASH-1018905 ExploitThird Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Not ApplicableThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf PatchThird Party Advisory
https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8 Broken Link
https://github.com/lodash/lodash/pull/5065 PatchThird Party Advisory
https://security.netapp.com/advisory/ntap-20210312-0006/ Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JS-LODASH-1018905 ExploitThird Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Not ApplicableThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory

Track CVE-2020-28500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2026-4800Lodash code injection vulnerabilityImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did…EPSS 2.6%9.8CVE-2020-5413Vmware spring integration deserialization of untrusted data vulnerabilitySpring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default o…EPSS 4.4%9.8CVE-2019-0228Apache pdfbox xml external entity (xxe) vulnerabilityApache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…EPSS 9.5%9.1CVE-2019-10744Lodash prototype pollution vulnerabilityVersions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prop…EPSS 5.0%8.8CVE-2021-29505XStream XML deserialization allows remote command executionXStream versions prior to 1.4.17 deserialize untrusted XML input without adequate type restrictions, allowing an attacker with sufficient rights to e…EPSS 77%analysed8.8CVE-2020-26217XStream blocklist bypass allows remote code executionXStream before 1.4.14 can be tricked into deserializing attacker-controlled input that leads to OS command execution. Only deployments relying on XSt…EPSS 85%analysed8.8CVE-2020-15824Jetbrains kotlin improper privilege management vulnerabilityIn JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege e…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-28500), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.