Prototype pollution in Faye - #VU149943
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or steal messages.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the Node.js Faye server when handling HTTP requests. A remote attacker can send an HTTP request and leave the connection open to cause a denial of service or steal messages.
Message theft may depend on the engine in use and on affected clients using polling rather than WebSocket or EventSource transports.