๐Ÿ” CVE Alert

CVE-2026-49252

CRITICAL 9.9

deepstream is vulnerable to prototype pollution

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record. This issue has been fixed in version 10.0.5.

CWE CWE-1321
Vendor deepstreamio
Product deepstream.io
Published Jun 18, 2026
Stay Ahead of the Next One

Get instant alerts for deepstreamio deepstream.io

Be the first to know when new critical vulnerabilities affecting deepstreamio deepstream.io are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

deepstreamIO / deepstream.io
< 10.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/deepstreamIO/deepstream.io/security/advisories/GHSA-9v98-6g37-x9g6 github.com: https://github.com/deepstreamIO/deepstream.io/commit/54b8e2958a98df444b5b5d9a66e22872afd84e44