[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-UBUNTU-CVE-2026-27601":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":16,"duplicates":17,"related":18,"reserved_at":9,"published_at":19,"modified_at":20,"state":9,"summary":21,"references_raw":23,"kevs":46,"epss":9,"epss_history":47,"metrics":48,"affected":58},"UBUNTU-CVE-2026-27601","Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.",null,[],[],[],[14],{"_key":15},"CVE-2026-27601",[],[],[],"2026-03-03T23:15:00Z","2026-07-20T16:19:05.336962423Z",{"cisa_kev":22,"cisa_ransomware":22,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[24,30,34,38,42],{"url":25,"sources":26,"tags":28},"https://ubuntu.com/security/CVE-2026-27601",[27],"osv_ubuntu",[29],"REPORT",{"url":31,"sources":32,"tags":33},"https://www.cve.org/CVERecord?id=CVE-2026-27601",[27],[29],{"url":35,"sources":36,"tags":37},"https://github.com/jashkenas/underscore/commit/411e222eb0ca5d570cc4f6315c02c05b830ed2b4",[27],[29],{"url":39,"sources":40,"tags":41},"https://github.com/jashkenas/underscore/commit/a6e23ae9647461ec33ad9f92a2ecfc220eea0a84",[27],[29],{"url":43,"sources":44,"tags":45},"https://github.com/jashkenas/underscore/security/advisories/GHSA-qpx9-hpmf-5gmw",[27],[29],[],[],[49],{"source":27,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":50,"cvss_v4_0":55},{"baseScore":51,"baseSeverity":9,"vectorString":52,"impactScore":53,"exploitabilityScore":54},7.5,"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",6,10,{"baseScore":56,"baseSeverity":9,"vectorString":57,"impactScore":9,"exploitabilityScore":9},8.2,"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",[59],{"ecosystem":60,"name":61,"vendor":62,"product":61,"cpe_part":9,"purl_type":63,"purl_namespace":62,"purl_name":61,"source":9,"versions":64},"Ubuntu","ruby-rails-assets-underscore","ubuntu","deb",[65,69,70,71],{"version":66,"is_range":67,"range_type":68,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",true,"ecosystem",{"version":66,"is_range":67,"range_type":68,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":66,"is_range":67,"range_type":68,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":66,"is_range":67,"range_type":68,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9}]