Integer overflow in Immutable.js - CVE-2026-59879
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in List#set, List#setIn, List#updateIn, List#setSize, and the related functional set, setIn, and updateIn operations when processing a crafted index, size, or key-path segment in the range [2 ** 30, 2 ** 31). A remote attacker can send a specially crafted request to cause a denial of service.
A single small unauthenticated request can trigger an uncatchable infinite loop on an empty List or unbounded allocation leading to process abort on a populated List.
Affected software
IBM Tivoli Netcool/OMNIbus WebGUI
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
How to mitigate CVE-2026-59879
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41 iFix 001
Confluence Data Center - addressed in versions 9.2.24, 10.2.17
Jira Software Data Center - update to 10.3.24
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.11