← Back to CVE search

CVE-2026-14893

Instana Node.js tracer

Description

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.

CVSS 7.3EPSS 0.334%Risk 0.75
View source
Published
2026-07-28 21:17:26
Affected versions
==6.2.1
Type
Library
Last modified
2026-07-30 14:08:40
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L