Automated remediation exhausted
Devin attempted 2 fix cycles on
PR #419 but HIGH/CRITICAL findings remain.
Remaining findings
frontend/web-app/package-lock.json
- HIGH
CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution
- HIGH
CVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollution
- HIGH
CVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URL
- HIGH
CVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...
- HIGH
CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- HIGH
CVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
- HIGH
CVE-2026-44488: axios 1.15.0 → 1.16.0 — Allocation of Resources Without Limits or Throttling in Axios
- HIGH
CVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- HIGH
CVE-2026-44494: axios 1.15.0 → 1.16.0 — axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in config.proxy
- HIGH
CVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
- HIGH
CVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
- HIGH
CVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
- HIGH
CVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
- HIGH
GHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server Components
services/admin-service/Gemfile.lock
- CRITICAL
CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keys
- HIGH
CVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range header
- HIGH
CVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: Active Support: Denial of Service via large scientific notation strings
- HIGH
CVE-2026-45363: jwt 2.10.2 → ~> 2.10.3, >= 3.2.0 — ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
- HIGH
CVE-2026-47736: puma 6.6.1 → ~> 7.2.1, >= 8.0.2 — Puma PROXY Protocol v1 Parser A
Next steps
- Review the findings manually
- Check if the fixes require breaking API changes
- Consider adding justified suppressions to .trivyignore
with proper documentation
Opened automatically by the SAST auto-remediation pipeline.
Automated remediation exhausted
Devin attempted 2 fix cycles on
PR #419 but HIGH/CRITICAL findings remain.
Remaining findings
frontend/web-app/package-lock.json
CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype PollutionCVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollutionCVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URLCVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionCVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterCVE-2026-44488: axios 1.15.0 → 1.16.0 — Allocation of Resources Without Limits or Throttling in AxiosCVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)CVE-2026-44494: axios 1.15.0 → 1.16.0 — axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget inconfig.proxyCVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeCVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionCVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nCVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requestsGHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server Componentsservices/admin-service/Gemfile.lock
CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keysCVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range headerCVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: Active Support: Denial of Service via large scientific notation stringsCVE-2026-45363: jwt 2.10.2 → ~> 2.10.3, >= 3.2.0 — ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351CVE-2026-47736: puma 6.6.1 → ~> 7.2.1, >= 8.0.2 — Puma PROXY Protocol v1 Parser ANext steps
with proper documentation
Opened automatically by the SAST auto-remediation pipeline.