CVE-2026-29063
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
1.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-29063 betrifft die JavaScript-Bibliothek Immutable.js und ermöglicht Prototype Pollution. Diese Schwachstelle kann über die APIs mergeDeep(), mergeDeepWith(), merge(), Map.toJS() und Map.toObject() ausgenutzt werden. Eine erfolgreiche Ausnutzung kann zu unautorisierten Änderungen an Objekten führen, was die Integrität der Anwendung beeinträchtigen kann.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Betroffene Produkte
- cpe:2.3:a:immutable-js:immutable:*:*:*:*:*:node.js:*:*
- cpe:2.3:a:immutable-js:immutable:*:*:*:*:*:node.js:*:*
- cpe:2.3:a:immutable-js:immutable:*:*:*:*:*:node.js:*:*
Referenzen
- https://github.com/immutable-js/immutable-js/releases/tag/v3.8.3
- https://github.com/immutable-js/immutable-js/releases/tag/v4.3.8
- https://github.com/immutable-js/immutable-js/releases/tag/v5.1.5
- https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-...
- https://access.redhat.com/errata/RHSA-2026:11070
- https://access.redhat.com/errata/RHSA-2026:11217
- https://access.redhat.com/errata/RHSA-2026:11414
- https://access.redhat.com/errata/RHSA-2026:11858
- https://access.redhat.com/errata/RHSA-2026:11916
- https://access.redhat.com/errata/RHSA-2026:12118