Json8 Merge Patch Project maintains a narrowly scoped implementation library for JSON Merge Patch operations, a data-serialization utility with modest deployment breadth. The observed disclosure pattern reflects this niche role; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Json8 Merge Patch Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8268HIGH Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor. | Nov 9, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Json8 Merge Patch Project.
Media articles that mention a CVE ID that affects a product developed by Json8 Merge Patch Project — matched by CVE ID, not by vendor name.