EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in the npm/immutable library versions prior to 4.3.9 and 5.1.8. These flaws include algorithmic complexity denial-of-service issues stemming from hash collisions in Map and Set structures, as well as a critical integer overflow vulnerability in the List data structure. Attackers can exploit these weaknesses by supplying maliciously crafted input or specific index ranges to trigger excessive CPU consumption, infinite loops, or unbounded memory allocation. Successful exploitation poses a significant business risk by causing application crashes, stalling server event loops, and potentially leading to widespread service outages for applications processing untrusted user data.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in the npm/immutable library versions prior to 4.3.9 and 5.1.8. These flaws include algorithmic complexity denial-of-service issues stemming from hash collisions in Map and Set structures, as well as a critical integer overflow vulnerability in the List data structure. Attackers can exploit these weaknesses by supplying maliciously crafted input or specific index ranges to trigger excessive CPU consumption, infinite loops, or unbounded memory allocation. Successful exploitation poses a significant business risk by causing application crashes, stalling server event loops, and potentially leading to widespread service outages for applications processing untrusted user data.[emaillocker id="1283"]
Exploitation of these vulnerabilities poses a high risk of service disruption, potentially allowing a single malicious request to crash critical application servers. The impact on availability is severe, as successful attacks can halt processing entirely or cause silent data corruption, leading to operational downtime and loss of user trust. Organizations utilizing this library to process external input must treat this situation with high urgency to prevent persistent outages.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-xvcm-6775-5m9r
https://github.com/advisories/GHSA-v56q-mh7h-f735