THREAT OPS › Threat News › [NVD] CVE-2026-73649 (CRITICAL 9.8) — Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/c
[NVD] CVE-2026-73649 (CRITICAL 9.8) — Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/c
CVE-2026-73649 CVSS: 9.8 CRITICAL Published: 2026-08-13T18:18:20.793
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getR
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-73649cve
- CVE-2026-44966cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73649