---
id: CVE-2026-59879
title: >-
  immutable-js: Immutable.js: Denial of Service due to mishandling of large
  index values in List operations (CVE-2026-59879)
summary: >-
  A flaw was found in Immutable.js, a library providing persistent immutable
  data structures. This vulnerability occurs when specific List operations, such
  as List#set or List#setSize, are provided with an index or size value within a
  partic…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cvssSource: vendor
cwe:
  - CWE-1285
  - CWE-190
  - CWE-400
  - CWE-835
  - CWE-1284
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - cryostat 4
  - logging_subsystem_for_red_hat_openshift
  - migration_toolkit_for_containers
  - migration_toolkit_for_virtualization
  - multicluster_engine_for_kubernetes
  - network_observability_operator
  - node_healthcheck_operator
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_service_mesh 2
  - 3scale_api_management_platform 2
  - advanced_cluster_security 4
  - ansible_automation_platform 2
  - connectivity_link 1
  - edge_manager 1
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_gitops
  - openshift_virtualization 4
  - quay 3
  - satellite 6
  - self_service_automation_portal 2
  - advanced_cluster_management_for_kubernetes 2.14
  - discovery 2
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - quay 3.16
  - satellite 6.18
patched:
  - advanced_cluster_management_for_kubernetes 2.14
  - discovery 2
  - openshift_service_mesh 3.0
  - openshift_service_mesh 3.1
  - openshift_service_mesh 3.2
  - quay 3.16
  - satellite 6.18
published: '2026-07-08'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:24:46+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59879'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2498158'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59879'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59879'
  - url: >-
      https://github.com/immutable-js/immutable-js/commit/a1a1ee412dcaa380ab325196283d06594ffe4b84
  - url: >-
      https://github.com/immutable-js/immutable-js/commit/f0bc997d8eb9886aff2236635aa210a95a04304a
  - url: 'https://github.com/immutable-js/immutable-js/releases/tag/v4.3.9'
  - url: 'https://github.com/immutable-js/immutable-js/releases/tag/v5.1.8'
  - url: >-
      https://github.com/immutable-js/immutable-js/security/advisories/GHSA-v56q-mh7h-f735
  - url: 'https://access.redhat.com/errata/RHSA-2026:67539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69289'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68687'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68689'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68691'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68756'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68765'
  - url: 'https://github.com/immutable-js/immutable-js/releases/tag/v3.8.4'
  - url: 'https://github.com/advisories/GHSA-v56q-mh7h-f735'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
  - score-dispute
epss: 0.00543
epssPercentile: 0.44533
aliases:
  - GHSA-v56q-mh7h-f735
ecosystem: npm
scores:
  vendor: 5.3
  ghsa: 7.5
ingestedAt: '2026-07-21T18:53:06.514Z'
---

## Overview

A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a particular large range. An attacker could exploit this by providing specially crafted input, leading to an uncatchable infinite loop or unbounded memory allocation, ultimately causing a Denial of Service (DoS) for applications using the library.

## Vendor advisories

- **RHSA-2026:67539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67539)
- **RHSA-2026:69289** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69289)
- **RHSA-2026:68687** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.0 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68687)
- **RHSA-2026:68689** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.1 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68689)
- **RHSA-2026:68691** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 3.2 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68691)
- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)
- **RHSA-2026:68756** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68756)
- **RHSA-2026:68765** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68765)
- **Red Hat VEX** · Moderate · affected: Cryostat 4, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Containers, Migration Toolkit for Virtualization, Multicluster Engine for Kubernetes, Network Observability Operator, … · no fix planned: Migration Toolkit for Virtualization, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Security 4, Red Hat Enterprise Linux 10, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59879.json)

**immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations** — rated Moderate by Red Hat. Released 2026-07-08, updated 2026-09-21.

Affected:

- Cryostat 4
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Connectivity Link 1
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat Quay 3
- Red Hat Satellite 6
- Self-service automation portal 2

Fixed:

- Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Discovery 2
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat Quay 3.16
- Red Hat Satellite 6.18

No fix planned:

- Migration Toolkit for Virtualization
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Security 4
- Red Hat Enterprise Linux 10
- Cryostat 4
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Containers
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Service Mesh 2
- Red Hat Ansible Automation Platform 2
- Red Hat Connectivity Link 1
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat Quay 3
- Red Hat Satellite 6
- Self-service automation portal 2

Not affected:

- Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Discovery 2
- Red Hat Quay 3.16
- OpenShift Service Mesh 3
- Red Hat 3scale API Management Platform 2
- Red Hat Developer Hub
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 4

## Remediation

Before you apply this update, make sure all previously released errata
that are relevant to your system are applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67539
The containers required to run Discovery can be installed through discovery-installer
RPM. See the official documentation for more details. https://access.redhat.com/errata/RHSA-2026:69289
See Kiali 2.4.23 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat https://access.redhat.com/errata/RHSA-2026:68687

Workarounds / mitigations:

- To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort.

## Package advisory (CVE-2026-59879)

Affected packages:

- `immutable >= 5.0.0-beta.1, < 5.1.8`
- `immutable >= 4.0.0-rc.1, < 4.3.9`
- `immutable < 3.8.4`

Patched in:

- `immutable 5.1.8`
- `immutable 4.3.9`
- `immutable 3.8.4`

Source: https://github.com/advisories/GHSA-v56q-mh7h-f735
