Skip to content

chore(security): fix CVEs (2026-07-23) - #83

Open
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-07-23
Open

chore(security): fix CVEs (2026-07-23)#83
Kevintjuhz wants to merge 2 commits into
developfrom
cve-fixes-2026-07-23

Conversation

@Kevintjuhz

Copy link
Copy Markdown
Member

Security & dependency fixes — 2026-07-23

Automatically applied by /cve-fix. Patch and minor bumps only.

Security CVE fixes

Severity Package From To CVE GHSA Summary
high fast-uri 4.0.0 4.1.1 CVE-2026-16221 GHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiter
high immutable 5.1.7 5.1.8 CVE-2026-59880 GHSA-xvcm-6775-5m9r Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.M
low body-parser 1.20.5 1.20.6 CVE-2026-12590 GHSA-v422-hmwv-36x6 body-parser vulnerable to denial of service when invalid limit value silently di
medium tar 7.5.16 7.5.18 CVE-2026-59871 GHSA-w8wr-v893-vjvp node-tar: Process crash via PAX numeric path type confusion
low @babel/core 7.29.0 7.29.6 CVE-2026-49356 GHSA-4x5r-pxfx-6jf8 @babel/core: Arbitrary File Read via sourceMappingURL Comment

Major bumps requiring manual review are listed in the CVE manual review report.

- [high] fast-uri 4.0.0 → 4.1.1 (CVE-2026-16221, GHSA-v2hh-gcrm-f6hx)
- [high] immutable 5.1.7 → 5.1.8 (CVE-2026-59880, GHSA-xvcm-6775-5m9r)
- [low] body-parser 1.20.5 → 1.20.6 (CVE-2026-12590, GHSA-v422-hmwv-36x6)
- [medium] tar 7.5.16 → 7.5.18 (CVE-2026-59871, GHSA-w8wr-v893-vjvp)
- [low] @babel/core 7.29.0 → 7.29.6 (CVE-2026-49356, GHSA-4x5r-pxfx-6jf8)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant