CVE-2024-39011
Critical · CVSS 9.8chargeover redoc — Prototype Pollution leading to RCE / DoS
- CVSS
- 9.8
- nvd
- EPSS
- 0.91%
- 55th pct
- KEV
- No
- Class
- other
- CWE-1321, CWE-1321
Description
Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.
Search profile — drives PoC discovery
Symbols mergeObjectsredoc__proto__constructorprototype
Keywords CVE-2024-39011chargeover redocprototype pollutionmergeObjectsredoc v2.0.9-rc.69CWE-1321redoc prototype pollution PoC
Versions: v2.0.9-rc.69
References
Status: enriched · ingested 2026-06-15T18:00:58.000Z · profiled 2026-06-16T18:19:23.017Z