RHSA-2026:4630HighCVSS 8.2
Red Hat Security Advisory: Red Hat Data Grid 8.6.0 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions
🎯 Affected products1
- Red Hat Data Grid 8.6.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example.
🔗 References (4)
- selfhttps://access.redhat.com/errata/RHSA-2026:4630
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_data_grid/8.6/html-single/data_grid_operator_8.6_release_notes/index
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4630.json