CVE-2026-29063
immutable-js immutable-js, Cluster Observability Operator 1.5.0, Migration Toolkit for Virtualization 2.1 취약점
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
- 대응 우선순위
- 점검
- CVSS
- 8.7
- EPSS
- 0.98% 백분위 58.7% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.03.07