Skip to content

Update Socket patches: +8 patches - #481

Open
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551758711-daf8cf8c
Open

Update Socket patches: +8 patches#481
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551758711-daf8cf8c

Conversation

@socket-security

Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2026-32141 in pkg:npm/flatted@3.2.7 (Socket Patch)
    • Severity: HIGH
    • Summary: flatted vulnerable to unbounded recursion DoS in parse() revive phase
  • Added: CVE-2026-6322 in pkg:npm/fast-uri@3.1.0 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  • Added: CVE-2024-52798 in pkg:npm/path-to-regexp@0.1.7 (Socket Patch)
    • Severity: HIGH
    • Summary: path-to-regexp contains a ReDoS
  • Added: CVE-2026-6321 in pkg:npm/fast-uri@3.1.0 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to path traversal via percent-encoded dot segments
  • Added: CVE-2026-33671 in pkg:npm/picomatch@2.3.1 (Socket Patch)
    • Severity: HIGH
    • Summary: Picomatch has a ReDoS vulnerability via extglob quantifiers
  • Added: in pkg:npm/serialize-javascript@6.0.2 (Socket Patch)
    • Severity: HIGH
    • Summary: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
  • Added: CVE-2022-25883 in pkg:npm/semver@6.3.0 (Socket Patch)
    • Severity: HIGH
    • Summary: semver vulnerable to Regular Expression Denial of Service
  • Added: CVE-2022-25883 in pkg:npm/semver@7.3.8 (Socket Patch)
    • Severity: HIGH
    • Summary: semver vulnerable to Regular Expression Denial of Service

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 15 blob(s) added
- 0 blob(s) removed
- Manifest updated
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant