Uncontrolled recursion in Underscore.js - CVE-2026-27601

 

Uncontrolled recursion in Underscore.js - CVE-2026-27601

Published: March 3, 2026


Vulnerability identifier: #VU123432
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27601
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to an uncontrolled recursion within the _.flatten() and _.isEqual() function. A remote attacker can pass specially crafted input to the application and perform a denial of service attack.


Affected software

Underscore.js
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Object Storage Systems
Industry Solutions Workbench
MongoDB Enterprise Advanced with IBM
openEuler
IBM Security SOAR
nodejs-underscore
js-underscore

How to mitigate CVE-2026-27601

Install updates from vendor's website.

Underscore.js - update to 1.13.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Industry Solutions Workbench - update to 5.1.1
MongoDB Enterprise Advanced with IBM - update to 8.0.21
IBM Security SOAR - update to 51.0.9.2
nodejs-underscore - update to 1.13.8-1
js-underscore - update to 1.13.8-1
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69

External References

Related Security Bulletins