PatchSiren cyber security CVE debrief
CVE-2026-59880 immutable-js CVE debrief
CVE-2026-59880 is a denial-of-service vulnerability in Immutable.js, a JavaScript library for immutable data structures. Versions before 4.3.9 and 5.1.8 are affected. The vulnerability arises from the way Immutable.Map and Immutable.Set handle keys with the same 32-bit hash in a HashCollisionNode. An attacker who controls keys inserted into a Map can craft colliding keys to degrade insertion and lookup operations, consuming disproportionate CPU. This issue can be mitigated by updating to a fixed version and reviewing user-controlled input to Immutable.Map and Immutable.Set. The vulnerability impacts applications using Immutable.js versions before 4.3.9 and 5.1.8, particularly those with user-controlled input to Immutable.Map and Immutable.Set.
- Vendor
- immutable-js
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-10
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-10
Who should care
Developers and security teams using Immutable.js versions before 4.3.9 and 5.1.8 should prioritize updating to a fixed version to prevent potential denial-of-service attacks. This includes reviewing and limiting user-controlled input to Immutable.Map and Immutable.Set, and monitoring for unusual CPU consumption patterns in applications using Immutable.js. Security teams should also verify the affected scope and severity with the official advisory.
Technical summary
The vulnerability is caused by the linear scanning of a HashCollisionNode in Immutable.Map and Immutable.Set when keys share the same 32-bit hash. This allows an attacker to craft many colliding keys, degrading insertion and lookup operations to consume disproportionate CPU. The issue is fixed in versions 4.3.9 and 5.1.8. Affected product deployments should be identified and prioritized for updates. The vulnerability impacts applications using Immutable.js versions before 4.3.9 and 5.1.8, particularly those with user-controlled input to Immutable.Map and Immutable.Set.
Defensive priority
High
Recommended defensive actions
- Update Immutable.js to version 4.3.9 or 5.1.8
- Review and limit user-controlled input to Immutable.Map and Immutable.Set
- Monitor for unusual CPU consumption patterns in applications using Immutable.js
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-08T16:16:34.517Z and was last modified on 2026-07-10T18:01:31.563Z. The NVD entry is currently Awaiting Analysis. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the official advisory. The vulnerability affects Immutable.js versions before 4.3.9 and 5.1.8. Evidence is limited, and defenders should review user-controlled input and monitor CPU consumption.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-59880 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-59880
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-59880 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59880
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/immutable-js/immutable-js/commit/3dd7e5655012597a41873e328bf9142a8901527b
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/immutable-js/immutable-js/commit/e51d49fc612ded5ec4dfb94ff294d22074269b0f
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/immutable-js/immutable-js/releases/tag/v4.3.9
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/immutable-js/immutable-js/releases/tag/v5.1.8
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/immutable-js/immutable-js/security/advisories/GHSA-xvcm-6775-5m9r
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.