Uncontrolled recursion in Underscore.js - CVE-2026-27601
Published: March 3, 2026
Vulnerability identifier: #VU123432
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27601
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to an uncontrolled recursion within the _.flatten() and _.isEqual() function. A remote attacker can pass specially crafted input to the application and perform a denial of service attack.
Affected software
Underscore.js
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Object Storage Systems
Industry Solutions Workbench
MongoDB Enterprise Advanced with IBM
openEuler
IBM Security SOAR
nodejs-underscore
js-underscore
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Object Storage Systems
Industry Solutions Workbench
MongoDB Enterprise Advanced with IBM
openEuler
IBM Security SOAR
nodejs-underscore
js-underscore
How to mitigate CVE-2026-27601
Install updates from vendor's website.
Underscore.js - update to 1.13.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Industry Solutions Workbench - update to 5.1.1
MongoDB Enterprise Advanced with IBM - update to 8.0.21
IBM Security SOAR - update to 51.0.9.2
nodejs-underscore - update to 1.13.8-1
js-underscore - update to 1.13.8-1
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Industry Solutions Workbench - update to 5.1.1
MongoDB Enterprise Advanced with IBM - update to 8.0.21
IBM Security SOAR - update to 51.0.9.2
nodejs-underscore - update to 1.13.8-1
js-underscore - update to 1.13.8-1
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
External References
Related Security Bulletins
- Remote denial of service in Underscore.js
- openEuler 24.03 LTS SP1 update for nodejs-underscore
- openEuler 24.03 LTS update for nodejs-underscore
- openEuler 24.03 LTS SP3 update for nodejs-underscore
- openEuler 24.03 LTS SP2 update for nodejs-underscore
- IBM Industry Solutions Workbench update for Underscore.js
- IBM Security SOAR update for Underscore.js
- IBM Watson Discovery Cartridge update for Underscore
- Multiple vulnerabilities in IBM Cloud Object System
- MongoDB Enterprise Advanced with IBM Ops-Manager update for Underscore.js