CVE-2026-29063

NameCVE-2026-29063
DescriptionImmutable.js provides many Persistent Immutable data structures. Prior ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-immutable (PTS)bullseye3.8.2+dfsg-3vulnerable
bookworm4.1.0-3vulnerable
sid, forky, trixie4.3.4-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-immutablesource(unstable)(unfixed)

Notes

Fixed by: https://github.com/immutable-js/immutable-js/commit/faeb58b0cc71ed351dc51f672a95ae21bc859ef5 (v4.3.8)
Fixed by: https://github.com/immutable-js/immutable-js/commit/94bcd3c79972db4afffd8d1e5aab415880098b05 (v4.3.8)

Search for package or bug name: Reporting problems