IBM Support

IT49580: SECURITY APAR:CVE-2025-62718,2026-(39865,40175,42033,42034,42035,42036,42037,42038,42039,42040,42041,42042,42043,42044,42264)

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • CVE-2025-62718: Incorrect hostname normalization when checking
    NO_PROXY rules allows requests to loopback addresses (like
    localhost.) or IPv6 literals ([::1]) to bypass protection,
    leading to potential SSRF.
    
    CVE-2026-39865: A state corruption bug in the HTTP/2 session
    cleanup logic allows a malicious server to crash the client
    process via concurrent session closures.
    
    CVE-2026-40175: A "Gadget" attack chain vulnerability where
    prototype pollution in third-party dependencies can be escalated
    into Remote Code Execution (RCE) or an AWS IMDSv2 bypass.
    
    CVE-2026-42033: Lack of hasOwnProperty guards when reading keys
    allows a prototype pollution vulnerability to silently
    intercept/modify JSON responses or hijack HTTP transport
    credentials.
    
    CVE-2026-42034: Bypasses the maxBodyLength limit for stream
    request bodies when maxRedirects is set to 0, allowing oversized
    streamed uploads to be fully sent.
    
    CVE-2026-42035: A prototype pollution gadget in the HTTP adapter
    lets an attacker inject arbitrary HTTP headers into outgoing
    requests by misidentifying plain object payloads as FormData.
    
    CVE-2026-42036: Fails to enforce maxContentLength when
    responseType: 'stream' is utilized, causing unbounded downstream
    consumption by bypassing size limits.
    
    CVE-2026-42037: The FormDataPart constructor interpolates values
    directly into the Content-Type header without sanitizing CRLF
    sequences, allowing arbitrary MIME part header injections.
    
    CVE-2026-42038: An incomplete fix for NO_PROXY validation where
    pure string matching fails to resolve IP aliases, routing
    requests to 127.0.0.1 through the proxy anyway.
    
    CVE-2026-42039: Uncontrolled recursion in toFormData while
    walking deeply nested objects can crash the Node.js process with
    a RangeError.
    
    CVE-2026-42040: A character mapping error in
    AxiosURLSearchParams reverses safe percent-encoding of null
    bytes back into raw null bytes.
    
    CVE-2026-42041: A prototype pollution gadget using JavaScript's
    in operator on validateStatus can force all HTTP error responses
    (e.g., 401, 500) to be treated as successful.
    
    CVE-2026-42042: XSRF token protection uses truthy/falsy logic
    instead of strict booleans, allowing non-boolean values to
    short-circuit the same-origin check and leak tokens to
    cross-origin servers.
    
    CVE-2026-42043: An incomplete fix for CVE-2025-62718 allows
    attackers to completely bypass NO_PROXY protections by using any
    address in the 127.0.0.0/8 range.
    
    CVE-2026-42044: A high-severity prototype pollution gadget via
    an unvalidated parseReviver function allows invisible, surgical
    modification of all incoming JSON API responses.
    
    CVE-2026-42264: Five specific config properties are read without
    hasOwnProperty guards, making them exploitable as prototype
    pollution gadgets to alter outbound HTTP requests.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Storage Insights users                                   *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * SECURITY APAR FOR                                            *
    * CVE-2025-62718,2026-(39865,40175,42033,42034,42035           *
    * ,42036,42037,42038,42039,42040,42041,42042,42043,42044,42264 *
    * )                                                            *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

  • The fix for this APAR is contained in the following release:
    
    IBM Storage Insights 2Q26   [ 54X-IBM-SI ]
    ( release target 2Q 2026 / June )
    
    To protect IBM Storage Insights against emerging
    security vulnerabilities, the service was updated to
    protected against vulnerabilities.
    
    No action is required, there is nothing that you need
    to do following the IBM Storage Insights upgrade.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT49580

  • Reported component name

    STORAGE INSIGHT

  • Reported component ID

    5608TPCSI

  • Reported release

    54X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-06-18

  • Closed date

    2026-06-18

  • Last modified date

    2026-06-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    STORAGE INSIGHT

  • Fixed component ID

    5608TPCSI

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSQRB8","label":"IBM Storage Insights"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"54X","Line of Business":{"code":"LOB69","label":"Storage TPS"}}]

Document Information

Modified date:
18 June 2026