CVE-2026-27601 describes a Denial of Service (DoS) vulnerability in Underscore.js versions prior to 1.13.8, affecting the _.flatten and _.isEqual functions. This flaw allows an unauthenticated attacker to trigger a stack overflow by providing specially crafted, deeply recursive input, leading to application unavailability. While the attack complexity is low, specific conditions regarding data structure and comparison paths must be met for successful exploitation. There is currently no evidence of active exploitation, nor are there public exploit codes or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.8CPE matchmatch criteria | cpe:2.3:a:underscorejs:underscore:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.