web3js CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

web3js vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to web3js, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-57329 web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence. [email protected] 7.5 0.05% 2025-09-24 2025-10-20
CVE-2025-57330 The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence. [email protected] 7.5 0.05% 2025-09-24 2025-10-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence