Prototype pollution in Faye - #VU149943

 

Prototype pollution in Faye - #VU149943

Published: September 15, 2026


Vulnerability identifier: #VU149943
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service or steal messages.

The vulnerability exists due to improperly controlled modification of object prototype attributes in the Node.js Faye server when handling HTTP requests. A remote attacker can send an HTTP request and leave the connection open to cause a denial of service or steal messages.

Message theft may depend on the engine in use and on affected clients using polling rather than WebSocket or EventSource transports.


Affected software

Faye

Remediation

Install security update from vendor's website.

Faye - update to 1.4.2

External References

Related Security Bulletins