Skip to content
VulniPulse
Medium4.3Red Hat Linux

Medium [CVE-2026-15187] Prototype pollution vulnerability allows remote attackers to modify object attributes

This medium-severity Red Hat Linux advisory covers CVE-2026-15187 affecting Red Hat Hardened Images, Cryostat 4, Migration Toolkit for Containers.

CVE-2026-15187 Published Jul 9, 2026Updated by vendor Jul 9, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API.

The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely.

The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.

A flaw was found in enquirer, a command-line prompt tool. A remote attacker could exploit a vulnerability in the `Enquirer.set` function by manipulating the `question.name` argument.

This improper handling of object prototype attributes can lead to prototype pollution, allowing an attacker to modify the behavior of an application. This could result in unexpected application behavior or potentially lead to further attacks.

This could lead to unexpected application behavior in Red Hat products that use `enquirer` to process untrusted input, as an attacker could modify object attributes. The public availability of an exploit increases the risk.

Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-915.

Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; and 17 more.

Affected versions
  • 2.4.1

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Fixed versions
  • rust-main-1.96.1-1.hum1
  • RHSA-2026:34975

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.