[GHSA-v56q-mh7h-f735] Immutable.js List 32-bit trie overflow → unrecoverable DoS - #9519
Ryan-Leber wants to merge 1 commit into
Conversation
|
Hi there @jdeniau! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟡 Changes recommended
Overlapping ranges still mark 3.8.4 affected, and the stale timestamp may prevent downstream refreshes.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates the Immutable.js advisory to recognize the 3.x patch release and revise severity metadata.
Changes:
- Adds
3.8.4as a fixed version. - Removes the CVSS v3 vector.
- Updates the modification timestamp.
File summaries
| File | Description |
|---|---|
GHSA-v56q-mh7h-f735.json |
Revises affected versions, severity, and metadata. |
Review details
Suppressed comments (1)
advisories/github-reviewed/2026/07/GHSA-v56q-mh7h-f735/GHSA-v56q-mh7h-f735.json:69
- This new 0-to-3.8.4 range is unioned with the existing 0-to-4.3.9 range, so 3.8.4 is still reported as affected. Split the earlier range at the 4.x introduction (the companion GHSA-xvcm-6775-5m9r uses 4.0.0-beta.1) and retain this separate 3.x range so the patch is effective.
"introduced": "0"
},
{
"fixed": "3.8.4"
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "schema_version": "1.4.0", | ||
| "id": "GHSA-v56q-mh7h-f735", | ||
| "modified": "2026-07-21T18:36:27Z", | ||
| "modified": "2026-07-21T18:36:31Z", |
|
Hi, there is 4 PR opened already : https://github.com/github/advisory-database/pulls?q=sort%3Aupdated-desc+is%3Apr+state%3Aopen+GHSA-v56q-mh7h-f735 Waiting for someone at github to merge this |
Updates
Comments
Version 3 has been patched but this CVE has not been updated to reflect that.
https://github.com/immutable-js/immutable-js/releases/tag/v3.8.4