APAR status
Closed as program error.
Error description
CVE-2025-62718: Incorrect hostname normalization when checking NO_PROXY rules allows requests to loopback addresses (like localhost.) or IPv6 literals ([::1]) to bypass protection, leading to potential SSRF. CVE-2026-39865: A state corruption bug in the HTTP/2 session cleanup logic allows a malicious server to crash the client process via concurrent session closures. CVE-2026-40175: A "Gadget" attack chain vulnerability where prototype pollution in third-party dependencies can be escalated into Remote Code Execution (RCE) or an AWS IMDSv2 bypass. CVE-2026-42033: Lack of hasOwnProperty guards when reading keys allows a prototype pollution vulnerability to silently intercept/modify JSON responses or hijack HTTP transport credentials. CVE-2026-42034: Bypasses the maxBodyLength limit for stream request bodies when maxRedirects is set to 0, allowing oversized streamed uploads to be fully sent. CVE-2026-42035: A prototype pollution gadget in the HTTP adapter lets an attacker inject arbitrary HTTP headers into outgoing requests by misidentifying plain object payloads as FormData. CVE-2026-42036: Fails to enforce maxContentLength when responseType: 'stream' is utilized, causing unbounded downstream consumption by bypassing size limits. CVE-2026-42037: The FormDataPart constructor interpolates values directly into the Content-Type header without sanitizing CRLF sequences, allowing arbitrary MIME part header injections. CVE-2026-42038: An incomplete fix for NO_PROXY validation where pure string matching fails to resolve IP aliases, routing requests to 127.0.0.1 through the proxy anyway. CVE-2026-42039: Uncontrolled recursion in toFormData while walking deeply nested objects can crash the Node.js process with a RangeError. CVE-2026-42040: A character mapping error in AxiosURLSearchParams reverses safe percent-encoding of null bytes back into raw null bytes. CVE-2026-42041: A prototype pollution gadget using JavaScript's in operator on validateStatus can force all HTTP error responses (e.g., 401, 500) to be treated as successful. CVE-2026-42042: XSRF token protection uses truthy/falsy logic instead of strict booleans, allowing non-boolean values to short-circuit the same-origin check and leak tokens to cross-origin servers. CVE-2026-42043: An incomplete fix for CVE-2025-62718 allows attackers to completely bypass NO_PROXY protections by using any address in the 127.0.0.0/8 range. CVE-2026-42044: A high-severity prototype pollution gadget via an unvalidated parseReviver function allows invisible, surgical modification of all incoming JSON API responses. CVE-2026-42264: Five specific config properties are read without hasOwnProperty guards, making them exploitable as prototype pollution gadgets to alter outbound HTTP requests.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: * * IBM Storage Insights users * **************************************************************** * PROBLEM DESCRIPTION: * * SECURITY APAR FOR * * CVE-2025-62718,2026-(39865,40175,42033,42034,42035 * * ,42036,42037,42038,42039,42040,42041,42042,42043,42044,42264 * * ) * **************************************************************** * RECOMMENDATION: * ****************************************************************
Problem conclusion
The fix for this APAR is contained in the following release: IBM Storage Insights 2Q26 [ 54X-IBM-SI ] ( release target 2Q 2026 / June ) To protect IBM Storage Insights against emerging security vulnerabilities, the service was updated to protected against vulnerabilities. No action is required, there is nothing that you need to do following the IBM Storage Insights upgrade.
Temporary fix
Comments
APAR Information
APAR number
IT49580
Reported component name
STORAGE INSIGHT
Reported component ID
5608TPCSI
Reported release
54X
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2026-06-18
Closed date
2026-06-18
Last modified date
2026-06-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
STORAGE INSIGHT
Fixed component ID
5608TPCSI
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSQRB8","label":"IBM Storage Insights"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"54X","Line of Business":{"code":"LOB69","label":"Storage TPS"}}]
Document Information
Modified date:
18 June 2026