CVE-2026-49252
Impact
Prototype pollution in deepstream server v <=10.0.4. Potential privilege escalation from any authenticated user with write permission to any record.
Patches
Yes, upgrade to v10.0.5
Workarounds
Filter out all messages containing the path proto, constructor, prototype, before they reach the server's message pipeline
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/deepstreamIO/deepstream.io/security/advisories/GHSA-9v98-6g37-x9g6, https://nvd.nist.gov/vuln/detail/CVE-2026-49252, https://github.com/deepstreamIO/deepstream.io/commit/54b8e2958a98df444b5b5d9a66e22872afd84e44, https://github.com/deepstreamIO/deepstream.io