NVD disclosure day

Published threat advisories for April 10, 2026

CVE advisoryCRITICAL

CVE-2026-40190

LangSmith SDK Prototype Pollution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The LangSmith Client SDK for Node.js has a vulnerability that allows an attacker controlling data keys to pollute `Object.prototype`, affecting all objects in the Node.js process. This could lead to unintended service behavior and impact application logic. Uncertainty exists regarding whether the `createAnonymizer()` A

CVE advisoryCRITICAL

CVE-2026-5483

OpenShift AI odh-dashboard Kubernetes Token Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in `odh-dashboard` for Red Hat OpenShift AI allows for disclosure of Kubernetes Service Account tokens via a NodeJS endpoint. If reachable, this could enable an attacker with limited privileges to gain unauthorized access to Kubernetes resources. Confirming affected environments and understanding potential impac