Immutable.js disclosed and patched CVE-2026-59880, a high-severity algorithmic complexity denial-of-service flaw in Immutable.Map and Immutable.Set that lets attackers drive excessive CPU usage by supplying many keys with the same 32-bit hash. In affected versions before 4.3.9 and 5.1.8, colliding keys were placed into HashCollisionNode buckets that were scanned linearly during inserts and lookups, enabling remote hash-flooding through attacker-controlled objects passed into common code paths such as Immutable.Map(obj), Immutable.fromJS(obj), merge, and mergeDeep.
The fix, released in Immutable.js 4.3.9 and 5.1.8, changes collision handling by adding a per-process seeded secondary hash used internally to index large collision buckets while preserving the library's public deterministic hash() behavior. Project commits and release notes say the update prevents the prior degradation toward near-O(n²) behavior, includes tests covering thousands of crafted colliding keys such as "Aa"/"BB" families, merge operations, transient and persistent maps, sets, and custom objects with identical hashCode() values, and addresses the issue tracked as GHSA-xvcm-6775-5m9r and CWE-407.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-59880 was publicly disclosed as a high-severity algorithmic complexity denial-of-service vulnerability in Immutable.js affecting Immutable.Map and Immutable.Set before versions 4.3.9 and 5.1.8. The disclosure states that colliding 32-bit hashes could force linear scans and disproportionate CPU consumption during insertion and lookup.
Immutable.js released version 5.1.8, which fixes the large hash-collision bucket indexing issue in Map and another security issue in List handling. The release notes identify GHSA-xvcm-6775-5m9r among the addressed advisories.
Immutable.js released version 4.3.9, which fixes the hash-collision bucket lookup issue in Map along with another security issue in List handling. The release notes state that the update addresses GitHub Security Advisories including GHSA-xvcm-6775-5m9r.
Immutable.js published security-relevant code changes that mitigate hash-flooding denial-of-service risk in Map and Set collision handling by indexing large hash-collision buckets with a secondary internal hash. The change was published in commits 3dd7e5655012597a41873e328bf9142a8901527b and e51d49fc612ded5ec4dfb94ff294d22074269b0f.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.