Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-48714

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
Back to all
CVE

CVE-2026-48714

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

Impact

i18next-http-middleware ≤ 3.9.6's missingKeyHandler blocked the literal request-body keys protoconstructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "proto.polluted". Downstream backends that split the missing-key string on a configured keySeparator (notably i18next-fs-backend ≤ 2.6.5) hand these keys to an unguarded setPath() walker that writes to Object.prototype.

Applications that expose missingKeyHandler to untrusted input AND use i18next-fs-backend ≤ 2.6.5 are directly exploitable for remote prototype pollution. Other downstream backends that split the missing-key string the same way may be similarly affected.

Depending on the host application, polluted prototype properties may cause crashes, corrupted translation behaviour, configuration poisoning, or bypasses of property-based security checks.

Patches

Fixed in i18next-http-middleware 3.9.7. A new utils.hasUnsafeKeySegment(key, keySeparator) helper is now used by missingKeyHandler; the configured i18next.options.keySeparator is honoured (default .false disables segment splitting and only the literal-key denylist applies). Legitimate dotted keys (e.g. "header.title") are unaffected.

The root-cause fix has been shipped in i18next-fs-backend 2.6.6 — see the companion advisory.

Workarounds

If users cannot upgrade immediately:

  • Do not expose missingKeyHandler to untrusted users (mount it behind authentication, or remove the route).
  • Add a request-body filter ahead of the handler that rejects any top-level key containing protoconstructor, or prototype after splitting on a configured keySeparator.
  • Disable missing-key persistence (saveMissing: false) when accepting writes from untrusted input.

Resources

  • Original report by @codeswhite.
  • Companion advisory in i18next-fs-backendGHSA-2933-q333-qg83.
  • Previous i18next-http-middleware security release: GHSA-5fgg-jcpf-8jjw and GHSA-c3h8-g69v-pjrg (in 3.9.3).

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Related Resources

No items found.

References

https://github.com/i18next/i18next-http-middleware/security/advisories/GHSA-f49m-vf83-692w, https://nvd.nist.gov/vuln/detail/CVE-2026-48714, https://github.com/i18next/i18next-http-middleware/commit/7c6d26f137d3e940b8d229ca148bca38845faf49, https://github.com/i18next/i18next-http-middleware

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00419%
EPSS Percentile
0.33966%
Introduced Version
0,3.0.2,1.0.0
Fix Available
3.9.7

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading