IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7281349 |
|
History
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. | |
| Title | IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image | |
| First Time appeared |
Ibm
Ibm observability With Instana Agent |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:ibm:observability_with_instana_agent:1.0.320:*:*:*:*:*:*:* cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm observability With Instana Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-07-28T20:36:57.507Z
Updated: 2026-07-28T20:36:57.507Z
Reserved: 2026-07-06T18:19:15.930Z
Link: CVE-2026-14893
No data.
No data.
No data.