CVE-2026-91860: Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge

Published Sep 30, 2026
·
Updated

A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application.

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:

Product version Vaadin 23.0.0 - 23.6.13 Vaadin 24.0.0 - 24.9.20 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6

Mitigation Upgrade to 23.6.14 Upgrade to 24.9.21 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer

Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.

Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7

npm packages npm package Vulnerable versions Fixed version @vaadin/charts 23.0.0 - 23.6.4 >=23.6.5 @vaadin/charts 24.0.0 - 24.9.17 >=24.9.18 @vaadin/charts 24.10.0 - 24.10.4 >=24.10.5 @vaadin/charts 25.0.0 - 25.1.11 >=25.1.12 @vaadin/charts 25.2.0 - 25.2.8 >=25.2.9 @vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18 @vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5 @vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12 @vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9

Affected Software

6 affected components
Vaadin Vaadin>=23.0.0<=23.6.13, >=24.0.0<=24.9.20, >=24.10.0<=24.10.9, >=25.0.0<=25.1.11, >=25.2.0<=25.2.6
maven/com.vaadin/vaadin>=23.0.0<=23.6.13, >=24.0.0<=24.9.20, >=24.10.0<=24.10.9, >=25.0.0<=25.1.11, >=25.2.0<=25.2.6
maven/com.vaadin/vaadin-core>=24.7.0<=24.9.20, >=24.10.0<=24.10.9, >=25.0.0<=25.1.11, >=25.2.0<=25.2.6
maven/com.vaadin/vaadin-charts-flow>=23.0.0<=23.6.13, >=24.0.0<=24.9.20, >=24.10.0<=24.10.9, >=25.0.0<=25.1.11, >=25.2.0<=25.2.6
npm/@vaadin/charts>=23.0.0<=23.6.4, >=24.0.0<=24.9.17, >=24.10.0<=24.10.4, >=25.0.0<=25.1.11, >=25.2.0<=25.2.8
npm/@vaadin/component-base>=24.7.0<=24.9.17, >=24.10.0<=24.10.4, >=25.0.0<=25.1.11, >=25.2.0<=25.2.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @vaadin/charts to a version that resolves this vulnerability.

    Fixed in 23.6.5
  2. Upgrade

    Upgrade @vaadin/charts to a version that resolves this vulnerability.

    Fixed in 24.9.18
  3. Upgrade

    Upgrade @vaadin/charts to a version that resolves this vulnerability.

    Fixed in 24.10.5
  4. Upgrade

    Upgrade @vaadin/charts to a version that resolves this vulnerability.

    Fixed in 25.1.12
  5. Upgrade

    Upgrade @vaadin/charts to a version that resolves this vulnerability.

    Fixed in 25.2.9
  6. Upgrade

    Upgrade @vaadin/component-base to a version that resolves this vulnerability.

    Fixed in 24.9.18
  7. Upgrade

    Upgrade @vaadin/component-base to a version that resolves this vulnerability.

    Fixed in 24.10.5
  8. Upgrade

    Upgrade @vaadin/component-base to a version that resolves this vulnerability.

    Fixed in 25.1.12
  9. Upgrade

    Upgrade @vaadin/component-base to a version that resolves this vulnerability.

    Fixed in 25.2.9
  10. Upgrade

    Upgrade com.vaadin:vaadin to a version that resolves this vulnerability.

    Fixed in 23.6.14
  11. Upgrade

    Upgrade com.vaadin:vaadin to a version that resolves this vulnerability.

    Fixed in 24.9.21
  12. Upgrade

    Upgrade com.vaadin:vaadin to a version that resolves this vulnerability.

    Fixed in 24.10.10
  13. Upgrade

    Upgrade com.vaadin:vaadin to a version that resolves this vulnerability.

    Fixed in 25.1.12
  14. Upgrade

    Upgrade com.vaadin:vaadin to a version that resolves this vulnerability.

    Fixed in 25.2.7
  15. Upgrade

    Upgrade com.vaadin:vaadin-charts-flow to a version that resolves this vulnerability.

    Fixed in 23.6.14
  16. Upgrade

    Upgrade com.vaadin:vaadin-charts-flow to a version that resolves this vulnerability.

    Fixed in 24.9.21
  17. Upgrade

    Upgrade com.vaadin:vaadin-charts-flow to a version that resolves this vulnerability.

    Fixed in 24.10.10
  18. Upgrade

    Upgrade com.vaadin:vaadin-charts-flow to a version that resolves this vulnerability.

    Fixed in 25.1.12
  19. Upgrade

    Upgrade com.vaadin:vaadin-charts-flow to a version that resolves this vulnerability.

    Fixed in 25.2.7
  20. Upgrade

    Upgrade com.vaadin:vaadin-core to a version that resolves this vulnerability.

    Fixed in 24.9.21
  21. Upgrade

    Upgrade com.vaadin:vaadin-core to a version that resolves this vulnerability.

    Fixed in 24.10.10
  22. Upgrade

    Upgrade com.vaadin:vaadin-core to a version that resolves this vulnerability.

    Fixed in 25.1.12
  23. Upgrade

    Upgrade com.vaadin:vaadin-core to a version that resolves this vulnerability.

    Fixed in 25.2.7

Event History

Sep 30, 2026
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using affected Vaadin Charts or Vaadin Component Base versions are exposed when they deep-merge an object not controlled by the application into a chart configuration or a component i18n property.

2

What must an attacker be able to influence?

An attacker must be able to supply or influence an object that the application deep-merges into a chart configuration or component i18n property. The merge can then write properties to Object.prototype, affecting every object in the running application.

3

How can I determine whether my dependency version is affected?

Check the version of the Vaadin artifacts in use. Affected ranges include com.vaadin:vaadin 23.0.0 through 23.6.13, 24.0.0 through 24.9.20, 24.10.0 through 24.10.9, 25.0.0 through 25.1.11, and 25.2.0 through 25.2.6; com.vaadin:vaadin-core is affected from 24.7.0 through 24.9.20.

4

What upgrade versions address the issue?

Upgrade to Vaadin 23.6.14, 24.9.21, 24.10.10, 25.1.12, or 25.2.7 or newer, as applicable to your release line. Vaadin versions 10–13 and 15–22 are unsupported and should be moved to a current 23, 24, or 25 release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203