CVE-2026-84368 | hapijs joi up to 17.1.1/17.13.5/18.2.4 Message lib/messages.js exports.compile/exports.merge messages prototype pollution
A vulnerability labeled as critical has been found in hapijs joi up to 17.1.1/17.13.5/18.2.4. This vulnerability affects the function exports.compile/exports.merge of the file lib/messages.js of the component Message Handler. Such manipulation of the argument messages leads to improperly controlled modification of object prototype attributes.
This vulnerability is uniquely identified as CVE-2026-84368. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More