← Retour aux CVEs
CVE-2026-29063
N/ADescription
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Details CVE
Score CVSS v3.1N/A
Publie3/6/2026
Derniere modification3/9/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-1321
References
https://github.com/immutable-js/immutable-js/releases/tag/v3.8.3(security-advisories@github.com)
https://github.com/immutable-js/immutable-js/releases/tag/v4.3.8(security-advisories@github.com)
https://github.com/immutable-js/immutable-js/releases/tag/v5.1.5(security-advisories@github.com)
https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-mvgw(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.