Skip to content

fix: fast-uri vulnerability#3295

Merged
jeromeraffin merged 1 commit into
mainfrom
fix/fast-uri-vulnerability
May 13, 2026
Merged

fix: fast-uri vulnerability#3295
jeromeraffin merged 1 commit into
mainfrom
fix/fast-uri-vulnerability

Conversation

@jeromeraffin
Copy link
Copy Markdown
Contributor

DESCRIPTION

├─ fast-uri
│ ├─ ID: 1117870
│ ├─ Issue: fast-uri vulnerable to path traversal via percent-encoded dot segments
│ ├─ URL: https://github.com/advisories/GHSA-q3j6-qgpj-74h6
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <=3.1.0
│ │
│ ├─ Tree Versions
│ │ └─ 3.0.6
│ │
│ └─ Dependents
│ └─ ajv@npm:8.18.0

└─ fast-uri
├─ ID: 1117884
├─ Issue: fast-uri vulnerable to host confusion via percent-encoded authority delimiters
├─ URL: https://github.com/advisories/GHSA-v39h-62p7-jpjc
├─ Severity: high
├─ Vulnerable Versions: <=3.1.1

├─ Tree Versions
│ └─ 3.0.6

└─ Dependents
└─ ajv@npm:8.18.0

Security vulnerabilities were found that were not ignored

@jeromeraffin jeromeraffin requested a review from a team as a code owner May 13, 2026 08:06
@github-actions
Copy link
Copy Markdown

👀 Visit Preview

@jeromeraffin jeromeraffin merged commit c3f6567 into main May 13, 2026
12 checks passed
@jeromeraffin jeromeraffin deleted the fix/fast-uri-vulnerability branch May 13, 2026 09:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants