USN-8411-1: Lodash vulnerabilities
Affected Software
1 affected component
npm/lodash
Event History
Jun 9, 2026
Advisory Published
via Ubuntu·06:06 PM
Data Sourced
via Ubuntu·06:06 PM
DescriptionAffected Software
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of USN-8411-1?
The severity of USN-8411-1 is rated as risk 33, indicating a moderate threat level.
2
How do I fix USN-8411-1?
To fix USN-8411-1, update the Lodash package to the latest version available through npm.
3
What vulnerabilities are addressed in USN-8411-1?
USN-8411-1 addresses multiple vulnerabilities including CVE-2026-4800, CVE-2026-2950, and CVE-2025-13465.
4
Which software is affected by USN-8411-1?
The USN-8411-1 vulnerability affects the npm package Lodash.
5
What are the potential impacts of not addressing USN-8411-1?
Not addressing USN-8411-1 may expose applications to security risks such as code injection or incorrect data handling.