RHSA-2026:4630HighCVSS 8.2

Red Hat Security Advisory: Red Hat Data Grid 8.6.0 security update

Published
March 16, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions

🎯 Affected products1

  • Red Hat Data Grid 8.6.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example.

🔗 References (4)