{"id":"CVE-2026-59879","title":"immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)","summary":"A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":["CWE-1285","CWE-190","CWE-400","CWE-835","CWE-1284"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["cryostat 4","logging_subsystem_for_red_hat_openshift","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multicluster_engine_for_kubernetes","network_observability_operator","node_healthcheck_operator","openshift_lightspeed","openshift_pipelines","openshift_service_mesh 2","3scale_api_management_platform 2","advanced_cluster_security 4","ansible_automation_platform 2","connectivity_link 1","edge_manager 1","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_ai_rhoai","openshift_container_platform 4","openshift_data_foundation 4","openshift_gitops","openshift_virtualization 4","quay 3","satellite 6","self_service_automation_portal 2","advanced_cluster_management_for_kubernetes 2.14","discovery 2","openshift_service_mesh 3.0","openshift_service_mesh 3.1","openshift_service_mesh 3.2","quay 3.16","satellite 6.18"],"patched":["advanced_cluster_management_for_kubernetes 2.14","discovery 2","openshift_service_mesh 3.0","openshift_service_mesh 3.1","openshift_service_mesh 3.2","quay 3.16","satellite 6.18"],"published":"2026-07-08","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:24:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59879"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498158"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59879"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59879"},{"url":"https://github.com/immutable-js/immutable-js/commit/a1a1ee412dcaa380ab325196283d06594ffe4b84"},{"url":"https://github.com/immutable-js/immutable-js/commit/f0bc997d8eb9886aff2236635aa210a95a04304a"},{"url":"https://github.com/immutable-js/immutable-js/releases/tag/v4.3.9"},{"url":"https://github.com/immutable-js/immutable-js/releases/tag/v5.1.8"},{"url":"https://github.com/immutable-js/immutable-js/security/advisories/GHSA-v56q-mh7h-f735"},{"url":"https://access.redhat.com/errata/RHSA-2026:67539"},{"url":"https://access.redhat.com/errata/RHSA-2026:69289"},{"url":"https://access.redhat.com/errata/RHSA-2026:68687"},{"url":"https://access.redhat.com/errata/RHSA-2026:68689"},{"url":"https://access.redhat.com/errata/RHSA-2026:68691"},{"url":"https://access.redhat.com/errata/RHSA-2026:69255"},{"url":"https://access.redhat.com/errata/RHSA-2026:68756"},{"url":"https://access.redhat.com/errata/RHSA-2026:68765"},{"url":"https://github.com/immutable-js/immutable-js/releases/tag/v3.8.4"},{"url":"https://github.com/advisories/GHSA-v56q-mh7h-f735"}],"tags":["csaf","vex","red-hat","ghsa","npm","score-dispute"],"epss":0.00543,"epssPercentile":0.44511,"aliases":["GHSA-v56q-mh7h-f735"],"ecosystem":"npm","scores":{"vendor":5.3,"ghsa":7.5},"ingestedAt":"2026-07-21T18:53:06.514Z","slug":"CVE-2026-59879","body":"## Overview\n\nA flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a particular large range. An attacker could exploit this by providing specially crafted input, leading to an uncatchable infinite loop or unbounded memory allocation, ultimately causing a Denial of Service (DoS) for applications using the library.\n\n## Vendor advisories\n\n- **RHSA-2026:67539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67539)\n- **RHSA-2026:69289** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69289)\n- **RHSA-2026:68687** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.0 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68687)\n- **RHSA-2026:68689** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.1 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68689)\n- **RHSA-2026:68691** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.2 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68691)\n- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)\n- **RHSA-2026:68756** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68756)\n- **RHSA-2026:68765** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68765)\n- **Red Hat VEX** · Moderate · affected: Cryostat 4, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Containers, Migration Toolkit for Virtualization, Multicluster Engine for Kubernetes, Network Observability Operator, … · no fix planned: Migration Toolkit for Virtualization, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Security 4, Red Hat Enterprise Linux 10, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json)\n\n**immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations** — rated Moderate by Red Hat. Released 2026-07-08, updated 2026-09-21.\n\nAffected:\n\n- Cryostat 4\n- Logging Subsystem for Red Hat OpenShift\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Service Mesh 2\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 2\n- Red Hat Connectivity Link 1\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat Quay 3\n- Red Hat Satellite 6\n- Self-service automation portal 2\n\nFixed:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2.14\n- Red Hat Discovery 2\n- Red Hat OpenShift Service Mesh 3.0\n- Red Hat OpenShift Service Mesh 3.1\n- Red Hat OpenShift Service Mesh 3.2\n- Red Hat Quay 3.16\n- Red Hat Satellite 6.18\n\nNo fix planned:\n\n- Migration Toolkit for Virtualization\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Enterprise Linux 10\n- Cryostat 4\n- Logging Subsystem for Red Hat OpenShift\n- Migration Toolkit for Containers\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Service Mesh 2\n- Red Hat Ansible Automation Platform 2\n- Red Hat Connectivity Link 1\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat Quay 3\n- Red Hat Satellite 6\n- Self-service automation portal 2\n\nNot affected:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2.14\n- Red Hat Discovery 2\n- Red Hat Quay 3.16\n- OpenShift Service Mesh 3\n- Red Hat 3scale API Management Platform 2\n- Red Hat Developer Hub\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nBefore you apply this update, make sure all previously released errata\nthat are relevant to your system are applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67539\nThe containers required to run Discovery can be installed through discovery-installer\nRPM. See the official documentation for more details. https://access.redhat.com/errata/RHSA-2026:69289\nSee Kiali 2.4.23 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat https://access.redhat.com/errata/RHSA-2026:68687\n\nWorkarounds / mitigations:\n\n- To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort.\n\n## Package advisory (CVE-2026-59879)\n\nAffected packages:\n\n- `immutable >= 5.0.0-beta.1, < 5.1.8`\n- `immutable >= 4.0.0-rc.1, < 4.3.9`\n- `immutable < 3.8.4`\n\nPatched in:\n\n- `immutable 5.1.8`\n- `immutable 4.3.9`\n- `immutable 3.8.4`\n\nSource: https://github.com/advisories/GHSA-v56q-mh7h-f735","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206374,"id":"CVE-2026-59879","ts":1789663223642,"field":"cvss","old":"7.5","new":"5.3"},{"seq":206373,"id":"CVE-2026-59879","ts":1789663223642,"field":"severity","old":"high","new":"medium"}]}