High severity7.5OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-59880
CVE-2026-59880
Description
Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted into a Map, such as through Immutable.Map(obj), Immutable.fromJS(obj), state.merge(userObject), or mergeDeep, to craft many colliding keys and degrade insertion and lookup to consume disproportionate CPU. This issue is fixed in versions 4.3.9 and 5.1.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- osv-coords15 versionspkg:apk/chainguard/arangodb-3.12pkg:apk/chainguard/authentik-2026.2pkg:apk/chainguard/keep-uipkg:apk/chainguard/keep-ui-fipspkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/vitess-24pkg:apk/wolfi/nextcloud-server-33pkg:apk/wolfi/rancher-api-uipkg:apk/wolfi/vitess-24pkg:apk/wolfi/vitess-23pkg:apk/chainguard/authentik-fips-2026.5pkg:apk/chainguard/authentik-2026.5pkg:apk/chainguard/vitess-23pkg:apk/chainguard/rancher-api-ui
< 3.12.9.4-r26+ 14 more
- (no CPE)range: < 3.12.9.4-r26
- (no CPE)range: < 2026.2.6-r11
- (no CPE)range: < 0.54.2-r3
- (no CPE)range: < 0.54.2-r5
- (no CPE)range: < 33.0.7-r1
- (no CPE)range: < 34.0.2-r7
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 33.0.7-r1
- (no CPE)range: < 1.2.3-r9
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 23.0.5-r6
- (no CPE)range: < 2026.5.6-r3
- (no CPE)range: < 2026.5.6-r4
- (no CPE)range: < 23.0.5-r6
- (no CPE)range: < 1.2.3-r9
v5.1.7, v5.1.6, v4.3.8, …+ 1 more
- (no CPE)range: v5.1.7, v5.1.6, v4.3.8, …
- (no CPE)range: <4.3.9, <5.1.8
Patches
Vulnerability mechanics
References
7- github.com/immutable-js/immutable-js/commit/3dd7e5655012597a41873e328bf9142a8901527bnvdPatch
- github.com/immutable-js/immutable-js/commit/e51d49fc612ded5ec4dfb94ff294d22074269b0fnvdPatch
- github.com/immutable-js/immutable-js/security/advisories/GHSA-xvcm-6775-5m9rnvdExploitMitigationVendor Advisory
- github.com/advisories/GHSA-xvcm-6775-5m9rghsaADVISORY
- github.com/immutable-js/immutable-js/releases/tag/v4.3.9nvdRelease Notes
- github.com/immutable-js/immutable-js/releases/tag/v5.1.8nvdRelease Notes
- nvd.nist.gov/vuln/detail/CVE-2026-59880ghsa
News mentions
0No linked articles in our index yet.