Skip to content

fix(deps): vuln minor upgrades — 8 packages (minor: 4 · patch: 4) [package.json] - #1473

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1791199299
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/0-1791199299

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 10 packages upgraded (MINOR changes included)

Manifests changed:

  • package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
axios 1.18.0 1.20.0 minor Transitive 14 HIGH, 9 MEDIUM
brace-expansion 5.0.9 5.0.12 patch Transitive 4 HIGH, 2 MEDIUM
brace-expansion 2.1.4 2.1.7 patch Transitive 4 HIGH, 2 MEDIUM
brace-expansion 1.1.18 1.1.21 patch Transitive 4 HIGH, 2 MEDIUM
fast-uri 3.1.6 3.1.8 patch Transitive 4 HIGH, 2 MEDIUM
dd-trace 5.56.0 5.130.0 minor Direct 2 HIGH
smol-toml 1.6.1 1.9.0 minor Transitive 2 HIGH
joi 17.13.6 17.13.8 patch Transitive 2 HIGH
ajv 6.12.6 6.15.0 minor Transitive 2 MEDIUM
fast-xml-parser 4.5.5 4.5.7 patch Transitive 2 MEDIUM

Security Details

🚨 Critical & High Severity (36 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
axios GHSA-3pq3-5fj3-cg6v HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.0 1.20.0 -
axios CVE-2026-101905 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.0 - -
axios GHSA-c29m-xwm3-cm6r HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.0 1.20.0 -
axios CVE-2026-101903 HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.0 - -
axios GHSA-542g-h47m-68v8 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.0 1.20.0 -
axios CVE-2026-101901 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.0 - -
axios GHSA-r4gj-5m52-g5wh HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.0 1.20.0 -
axios GHSA-mghh-pgcx-3jjj HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.0 1.20.0 -
axios CVE-2026-101898 HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.0 - -
axios CVE-2026-101909 HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.0 - -
axios GHSA-x97p-jq2g-jp4f HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.0 0.34.0 -
axios GHSA-m8m8-qj5v-23w3 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.0 1.20.0 -
axios CVE-2026-101907 HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.0 - -
axios CVE-2026-101906 HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.0 - -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 2.1.4 5.0.11 -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 5.0.10 -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 5.0.11 -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 5.0.9 5.0.11 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 5.0.9 - -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 - -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 2.1.4 - -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 - -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 5.0.9 5.0.10 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 2.1.4 - -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 2.1.4 5.0.10 -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 5.0.9 - -
dd-trace CVE-2026-50272 HIGH dd-trace: Improper parsing of W3C baggage headers may lead to DoS 5.56.0 - -
dd-trace GHSA-wxqq-gcq8-c443 HIGH dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS 5.56.0 5.100.0 -
fast-uri GHSA-58mr-gqgx-xq4g HIGH fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority 3.1.6 2.4.6 -
fast-uri GHSA-qw65-cvwx-89v3 HIGH fast-uri vulnerable to authority injection via an unvalidated port in serialize 3.1.6 2.4.6 -
fast-uri CVE-2026-84292 HIGH fast-uri vulnerable to authority injection via an unvalidated port in serialize 3.1.6 - -
fast-uri CVE-2026-84394 HIGH fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority 3.1.6 - -
joi GHSA-6h2x-m376-mqjq HIGH joi: Quadratic regular-expression backtracking in Joi.string().isoDate() 17.13.6 17.13.7 -
joi CVE-2026-92599 HIGH Joi before 17.13.7 and 18.2.6 ReDoS via isoDate 17.13.6 - -
smol-toml CVE-2026-85730 HIGH smol-toml: Denial of Service via malformed TOML documents 1.6.1 - -
smol-toml GHSA-7w5x-hrqm-74c2 HIGH smol-toml: Denial of Service via malformed TOML documents 1.6.1 1.7.1 -
ℹ️ Other Vulnerabilities (21)
Package CVE Severity Summary Unsafe Version Fixed In Case
ajv GHSA-2g4f-4pwh-qvx6 MODERATE ajv has ReDoS when using $data option 6.12.6 8.18.0 -
ajv CVE-2025-69873 MODERATE - 6.12.6 - -
axios CVE-2026-101908 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.0 - -
axios GHSA-vh66-26gq-q6x8 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.0 1.20.0 -
axios GHSA-4hqw-qxg8-jxx2 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.0 1.20.0 -
axios CVE-2026-101900 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.0 - -
axios GHSA-44g4-m2mj-wpvx MODERATE Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges 1.18.0 1.20.0 -
axios GHSA-9fr6-4gfg-395g MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.0 0.34.0 -
axios CVE-2026-101902 MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.0 - -
axios CVE-2026-101904 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.0 - -
axios GHSA-j8rh-479h-cp32 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.0 1.20.0 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 5.0.9 - -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 5.0.9 5.0.12 -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 2.1.4 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 - -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 2.1.4 - -
fast-uri GHSA-hrr3-gc8f-f4qj MODERATE fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets 3.1.6 2.4.7 -
fast-uri CVE-2026-86472 MODERATE fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets 3.1.6 - -
fast-xml-parser GHSA-gh4j-gqv2-49f6 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.5.5 5.7.0 -
fast-xml-parser CVE-2026-41650 MODERATE fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters 4.5.5 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant