Skip to content

deps: Upgrade plug to 1.19.3#3285

Merged
joshlarson merged 1 commit into
mainfrom
jdl/fix/upgrade-plug
Jun 25, 2026
Merged

deps: Upgrade plug to 1.19.3#3285
joshlarson merged 1 commit into
mainfrom
jdl/fix/upgrade-plug

Conversation

@joshlarson

Copy link
Copy Markdown
Contributor

Scope

CVE-2026-54892 reveals a defect in plug, where query params shaped a specific way can cause a denial-of-service by getting parsed in quadratic time.

This is fixed in version 1.19.3.

Asana Ticket: 📈 Upgrade Plug (CVE-2026-54892)

@joshlarson joshlarson requested a review from a team as a code owner June 25, 2026 12:18
@joshlarson joshlarson requested a review from lvachon1 June 25, 2026 12:18
@joshlarson joshlarson enabled auto-merge (squash) June 25, 2026 12:23
@joshlarson joshlarson merged commit bd5667a into main Jun 25, 2026
26 checks passed
@joshlarson joshlarson deleted the jdl/fix/upgrade-plug branch June 25, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants