Skip to content

[Security] Unresolved SAST findings on PR #419 #421

Description

@github-actions

Automated remediation exhausted

Devin attempted 2 fix cycles on
PR #419 but HIGH/CRITICAL findings remain.

Remaining findings

frontend/web-app/package-lock.json

  • HIGH CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution
  • HIGH CVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollution
  • HIGH CVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URL
  • HIGH CVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...
  • HIGH CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  • HIGH CVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  • HIGH CVE-2026-44488: axios 1.15.0 → 1.16.0 — Allocation of Resources Without Limits or Throttling in Axios
  • HIGH CVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  • HIGH CVE-2026-44494: axios 1.15.0 → 1.16.0 — axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in config.proxy
  • HIGH CVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  • HIGH CVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  • HIGH CVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
  • HIGH CVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
  • HIGH GHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server Components

services/admin-service/Gemfile.lock

  • CRITICAL CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keys
  • HIGH CVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range header
  • HIGH CVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
  • HIGH CVE-2026-45363: jwt 2.10.2 → ~> 2.10.3, >= 3.2.0 — ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
  • HIGH CVE-2026-47736: puma 6.6.1 → ~> 7.2.1, >= 8.0.2 — Puma PROXY Protocol v1 Parser A

Next steps

  • Review the findings manually
  • Check if the fixes require breaking API changes
  • Consider adding justified suppressions to .trivyignore
    with proper documentation

Opened automatically by the SAST auto-remediation pipeline.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions