Skip to content

fix(security): upgrade undici 7.22.0 → 7.24.4 to patch 6 CVEs#1

Merged
LucasFormiga merged 3 commits intomainfrom
copilot/analyze-and-upgrade-dependencies
Mar 19, 2026
Merged

fix(security): upgrade undici 7.22.0 → 7.24.4 to patch 6 CVEs#1
LucasFormiga merged 3 commits intomainfrom
copilot/analyze-and-upgrade-dependencies

Conversation

Copy link
Contributor

Copilot AI commented Mar 19, 2026

undici@7.22.0 (transitive via jsdompackages/react devDep) carried 6 unpatched CVEs across the 7.0.0–7.23.0 range, including three high-severity DoS vectors.

Vulnerabilities resolved

Advisory Severity Issue
GHSA-f269-vfmq-vjvj High WebSocket 64-bit length overflow → crash
GHSA-vrm6-8vpv-qv8q High Unbounded memory in WebSocket permessage-deflate
GHSA-v9p9-hfj2-hcw8 High Unhandled exception on invalid server_max_window_bits
GHSA-2mjp-6q6p-2qxm Moderate HTTP Request/Response Smuggling
GHSA-4992-7rv2-5pvq Moderate CRLF Injection via upgrade option
GHSA-phc3-fgpg-7m6h Moderate DoS via unbounded response buffering in DeduplicationHandler

Change

Lockfile-only — npm audit fix bumped the resolved undici version from 7.22.0 to 7.24.4. No source changes required; jsdom's ^7.21.0 range already satisfies 7.24.4.


📱 Kick off Copilot coding agent tasks wherever you are with GitHub Mobile, available on iOS and Android.

Copilot AI and others added 2 commits March 19, 2026 13:11
Co-authored-by: LucasFormiga <5132668+LucasFormiga@users.noreply.github.com>
Co-authored-by: LucasFormiga <5132668+LucasFormiga@users.noreply.github.com>
Copilot AI changed the title [WIP] Run npm audit and upgrade vulnerable dependencies fix(security): upgrade undici 7.22.0 → 7.24.4 to patch 6 CVEs Mar 19, 2026
Copilot AI requested a review from LucasFormiga March 19, 2026 13:14
@LucasFormiga LucasFormiga marked this pull request as ready for review March 19, 2026 13:14
@LucasFormiga LucasFormiga merged commit cbe08d4 into main Mar 19, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants