SB2026091518 - Prototype pollution in Faye



SB2026091518 - Prototype pollution in Faye

Published: September 15, 2026

Security Bulletin ID SB2026091518
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Prototype pollution (CVE-ID: N/A)

CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or steal messages.

The vulnerability exists due to improperly controlled modification of object prototype attributes in the Node.js Faye server when handling HTTP requests. A remote attacker can send an HTTP request and leave the connection open to cause a denial of service or steal messages.

Message theft may depend on the engine in use and on affected clients using polling rather than WebSocket or EventSource transports.


Remediation

Install update from vendor's website.