CVE-2026-25150

Prototype Pollution via FormData Processing in Qwik City

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails to sanitize dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service. This issue has been patched in version 1.19.0.


We have discovered 13,066 live websites that are affected by CVE-2026-25150.

Run a Free Instant Scan




Affected Software

Product  Qwik
Category Web Application Frameworks
Vulnerable Domains13,066 live websites (100% of Qwik install base)
Vulnerable Versions
  • from 0 through 1.19
Vulnerable Versions Count39 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')



Details

  • Published - Feb 3, 2026
  • Updated - Feb 4, 2026

Website Distribution by Country

Number of websites using CVE-2026-25150
United States9,478 websites
GB498 websites
Germany54 websites
Canada23 websites
Iran12 websites
France10 websites
Poland9 websites
Russia8 websites
Portugal8 websites

Website Distribution by TLD

Number of websites using CVE-2026-25150
.com7,924 websites
.de684 websites
.co.uk484 websites
.net454 websites
.info430 websites
.org144 websites
.co29 websites
.io8 websites
.it8 websites
.fr8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25150

Top websites that are affected by CVE-2026-25150. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.jobs United States*,***
***********.com United States*,***
**.com United States*,***
******.at Austria*,***
***********.com United States**,***
*******.online United States**,***
*******.com United States**,***
********.com United States**,***
***.ch United States**,***
*****.com United States**,***
See full domain list

FAQ

CVE-2026-25150 is Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in Qwik
A total of 13,066 websites have been identified as vulnerable to CVE-2026-25150, based on global website indexing conducted by WebTechSurvey.
The Qwik is affected by the CVE-2026-25150 vulnerability.
Qwik versions up to 1.19 are vulnerable to CVE-2026-25150.
CVE-2026-25150 is resolved in version 1.19 of Qwik.