{"api_version":"1","generated_at":"2026-07-23T12:53:03+00:00","cve":"CVE-2021-29491","urls":{"html":"https://cve.report/CVE-2021-29491","api":"https://cve.report/api/cve/CVE-2021-29491.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-29491","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-29491"},"summary":{"title":"CVE-2021-29491","description":"** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28860. Reason: This candidate is a reservation duplicate of CVE-2021-28860. Notes: All CVE users should reference CVE-2021-28860 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.","state":"REJECT","assigner":"cve@mitre.org","published_at":"2021-05-06 13:15:00","updated_at":"2023-11-07 03:32:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://security.netapp.com/advisory/ntap-20210622-0002/","name":"https://security.netapp.com/advisory/ntap-20210622-0002/","refsource":"CONFIRM","tags":[],"title":"CVE-2021-29491 Node.js Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4","name":"https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4","refsource":"CONFIRM","tags":[],"title":"Use of Potentially Dangerous Function in mixme · Advisory · adaltas/node-mixme · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-29491","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29491","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"29491","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mixme_project","cpe5":"mixme","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-29491","qid":"982057","title":"Nodejs (npm) Security Update for mixme (GHSA-79jw-6wg7-r9g4)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-29491","ASSIGNER":"cve@mitre.org","STATE":"REJECT"},"description":{"description_data":[{"lang":"eng","value":"** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28860. Reason: This candidate is a reservation duplicate of CVE-2021-28860. Notes: All CVE users should reference CVE-2021-28860 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage."}]}},"nvd":{"publishedDate":"2021-05-06 13:15:00","lastModifiedDate":"2023-11-07 03:32:00","problem_types":[],"metrics":[],"configurations":{"CVE_data_version":"4.0","nodes":[]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"29491","Ordinal":"204695","Title":"CVE-2021-29491","CVE":"CVE-2021-29491","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"29491","Ordinal":"1","NoteData":"Mixme is a library for recursive merging of Javascript objects. In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS). The problem is corrected starting with version 0.5.1; no workarounds are known to exist.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"29491","Ordinal":"2","NoteData":"2021-05-06","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"29491","Ordinal":"3","NoteData":"2021-06-22","Type":"Other","Title":"Modified"}]}}}