{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-13T16:53:41.947","vulnerabilities":[{"cve":{"id":"CVE-2026-25150","sourceIdentifier":"security-advisories@github.com","published":"2026-02-03T22:16:30.690","lastModified":"2026-02-10T20:10:16.513","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails to sanitize dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service. This issue has been patched in version 1.19.0."},{"lang":"es","value":"Qwik es un framework de javascript centrado en el rendimiento. Antes de la versión 1.19.0, existe una vulnerabilidad de contaminación de prototipos en la función formToObj() dentro del middleware @builder.io/qwik-city. La función procesa los nombres de los campos del formulario con notación de puntos (por ejemplo, user.name) para crear objetos anidados, pero no logra sanear nombres de propiedades peligrosos como __proto__, constructor y prototype. Esto permite a atacantes no autenticados contaminar Object.prototype enviando solicitudes HTTP POST manipuladas, lo que podría conducir a escalada de privilegios, omisión de autenticación o denegación de servicio. Este problema ha sido parcheado en la versión 1.19.0."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-1321"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qwik:qwik:*:*:*:*:*:node.js:*:*","versionEndExcluding":"1.19.0","matchCriteriaId":"8A329D09-A8EB-4297-8BD9-4E862179FE54"}]}]}],"references":[{"url":"https://github.com/QwikDev/qwik/commit/5f65bae2bc33e6ca0c21e4cfcf9eae05077716f7","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/QwikDev/qwik/security/advisories/GHSA-xqg6-98cw-gxhq","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}