Skip to content

fix(security): npm security fixes (2026-08-10) - #1450

Open
github-actions[bot] wants to merge 1 commit into
newjitsufrom
security/fix-npm-2026-08-10
Open

fix(security): npm security fixes (2026-08-10)#1450
github-actions[bot] wants to merge 1 commit into
newjitsufrom
security/fix-npm-2026-08-10

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

Batch npm dependency security fixes for moderate/high alerts from .dependabot-alerts.json.

Included fixes

  • CVE-2025-71330 (HIGH): image-size infinite-loop DoS in ICNS parser — image-size 0.5.5 → removed (via less 4.6.44.8.1)
  • CVE-2025-71329 (HIGH): image-size infinite-loop DoS in JXL/HEIF parsers — image-size 0.5.5 → removed (via less 4.6.44.8.1)
  • CVE-2026-67214 (HIGH): nanoid non-secure generator negative-size infinite loop — nanoid 5.1.115.1.16
  • CVE-2026-71850 (MEDIUM): hono SSR memo cross-request data disclosure — hono 4.12.274.13.1
  • CVE-2026-71848 (MEDIUM): hono language middleware algorithmic-complexity DoS — hono 4.12.274.13.1
  • CVE-2026-69207 (MEDIUM): hono CORS middleware ReDoS — hono 4.12.274.13.1
  • GHSA-55q2-fjhq-7xh7 (MEDIUM): dompurify detached-subtree XSS — dompurify 3.4.123.4.13
  • CVE-2026-16729 (MEDIUM): undici cookie attribute injection — undici 6.27.06.28.0, 7.28.07.29.0
  • CVE-2026-18446 (HIGH): fast-uri host confusion via backslash authority introducer — fast-uri 3.1.43.1.5
  • CVE-2026-15157 (MEDIUM): undici CRLF injection via blob-like body type — undici 6.27.06.28.0, 7.28.07.29.0
  • CVE-2026-16728 (MEDIUM): undici downstream response desynchronization via retry interceptor — undici 6.27.06.28.0, 7.28.07.29.0
  • CVE-2026-69192 (HIGH): ip-address octet parsing mismatch SSRF bypass — ip-address 10.2.010.5.0
  • CVE-2026-69185 (HIGH): socket.io-parser zero-attachment memory exhaustion — socket.io-parser 4.2.64.2.7
  • CVE-2026-69152 (HIGH): brace-expansion unbounded intermediate arrays DoS — brace-expansion 5.0.85.0.9
  • CVE-2026-14643 (MEDIUM): undici cache-control parsing information disclosure — undici 7.28.07.29.0
  • CVE-2026-13697 (HIGH): undici private-cache directive disclosure/crash — undici 7.28.07.29.0
  • CVE-2026-69198 (MEDIUM): ip-address CIDR classification bypass — ip-address 10.2.010.5.0
  • CVE-2026-54272 (MEDIUM): ip-address IPv4-mapped/NAT64 misclassification bypass — ip-address 10.2.010.5.0

Verification

  • pnpm install --no-frozen-lockfile succeeded.

Risks

  • No major-version dependency bumps were required.
  • less was bumped within major (4.6.44.8.1) to remove vulnerable image-size from the tree.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants