Visit NES for Lodash Home Page

Lodash 4.17 Release Notes

3 versions

Comprehensive release notes and changelog for Lodash 4.17, including security patches, bug fixes, and feature updates across all supported versions.

Apr 9, 2026
Latest: 4.17.25
3 Patched Vulnerabilities
VEX Statements

April 2026

Full Version:
4.17.23-lodash-4.17.25

Notes

  • This release contains backported security fixes to remediate two vulnerabilities.
  • Full version: @neverendingsupport/lodash@4.17.23-lodash-4.17.25

Bug Fixes

  • _.unset:
    • Block unsafe traversal via constructor and prototype.
      • This fixes a moderate-severity Prototype Pollution vulnerability (CVE-2026-2950).
  • _.omit:
    • Block unsafe traversal via constructor and prototype.
      • This fixes a moderate-severity Prototype Pollution vulnerability (CVE-2026-2950).
  • _.template:
    • Harden against code injection via options.imports.
      • This fixes a high-severity Code Injection vulnerability (CVE-2026-4800).

February 2026

4.17.24

Released Feb 19, 2026
Full Version:
4.17.23-lodash-4.17.24

Notes

  • This release contains no functional change from the OSS lodash v4.17.23.
  • This release mainlines OSS v4.17.23 into NES v4.17.24.
  • Full Version: @neverendingsupport/lodash@4.17.23-lodash-4.17.24

May 2024

4.17.22

Released May 17, 2024
Full Version:
4.17.21-lodash-4.17.22

Notes

  • This release contains no functional change from the OSS lodash v4.17.21.
  • This release mainlines OSS v4.17.21 into NES v4.17.22.
  • Full Version: @neverendingsupport/lodash@4.17.21-lodash-4.17.22

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.