Inefficient Algorithmic Complexity in Immutable.js - CVE-2026-59880
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in Immutable.Map and Immutable.Set collision bucket handling when processing attacker-controlled object keys. A remote attacker can supply many crafted colliding keys to cause a denial of service.
Applications are affected when untrusted input is used as keys in Immutable structures rather than only as values under fixed keys.
Affected software
IBM Tivoli Netcool/OMNIbus WebGUI
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
How to mitigate CVE-2026-59880
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41 iFix 001
Confluence Data Center - addressed in versions 9.2.24, 10.2.17
Jira Software Data Center - update to 10.3.24
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.11