← Vulnerability feed

Vulnerability record · CVE-2020-8203 · published 15 July 2020

CVE-2020-8203: Lodash allocation without limits vulnerability

Lodash · Lodash

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

7.4 CVSS 3.1 High EPSS 5.2% · top 7.8% CWE-770 · Allocation without limitsCWE-1321 · Prototype pollution
7.4CVSS 3.1 base score, v2 5.8
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8203 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2026-4800Lodash code injection vulnerabilityImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did…EPSS 2.6%9.8CVE-2020-5413Vmware spring integration deserialization of untrusted data vulnerabilitySpring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default o…EPSS 4.4%9.8CVE-2019-0228Apache pdfbox xml external entity (xxe) vulnerabilityApache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…EPSS 9.5%9.1CVE-2019-10744Lodash prototype pollution vulnerabilityVersions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying prop…EPSS 5.0%8.8CVE-2021-29505XStream XML deserialization allows remote command executionXStream versions prior to 1.4.17 deserialize untrusted XML input without adequate type restrictions, allowing an attacker with sufficient rights to e…EPSS 77%analysed8.8CVE-2020-26217XStream blocklist bypass allows remote code executionXStream before 1.4.14 can be tricked into deserializing attacker-controlled input that leads to OS command execution. Only deployments relying on XSt…EPSS 85%analysed8.8CVE-2020-15824Jetbrains kotlin improper privilege management vulnerabilityIn JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege e…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-8203), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.