Skip to content

[Security] Unresolved SAST findings on PR #486 #487

Description

@github-actions

Automated remediation exhausted

Devin attempted 2 fix cycles on
PR #486 but HIGH/CRITICAL findings remain.

Remaining findings

frontend/web-app/package-lock.json

  • HIGH CVE-2026-42033: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution
  • HIGH CVE-2026-42035: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: Arbitrary HTTP header injection via prototype pollution
  • HIGH CVE-2026-42043: axios 1.15.0 → 1.15.1, 0.31.1 — axios: Axios: NO_PROXY bypass via crafted URL
  • HIGH CVE-2026-42264: axios 1.15.0 → 1.15.2 — Axios is a promise based HTTP client for the browser and Node.js. From ...
  • HIGH CVE-2026-44486: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
  • HIGH CVE-2026-44487: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Information disclosure of proxy credentials via redirect flows
  • HIGH CVE-2026-44488: axios 1.15.0 → 1.16.0 — axios: Axios: Denial of Service due to unenforced request and response size limits
  • HIGH CVE-2026-44492: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
  • HIGH CVE-2026-44494: axios 1.15.0 → 1.16.0 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
  • HIGH CVE-2026-44495: axios 1.15.0 → 1.15.2, 0.31.1 — axios: Axios: Information disclosure due to prototype pollution vulnerability
  • HIGH CVE-2026-44496: axios 1.15.0 → 1.16.0, 0.32.0 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
  • HIGH CVE-2026-12143: form-data 4.0.5 → 2.5.6, 3.0.5, 4.0.6 — form-data is a library for creating readable multipart/form-data strea ...
  • HIGH CVE-2026-44573: next 14.1.3 → 15.5.16, 16.2.5 — next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
  • HIGH CVE-2026-44578: next 14.1.3 → 15.5.16, 16.2.5 — Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
  • HIGH GHSA-8h8q-6873-q5fj: next 14.1.3 → 15.5.16, 16.2.5 — Next.js Vulnerable to Denial of Service with Server Components
  • HIGH CVE-2026-48779: ws 6.2.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...
  • HIGH CVE-2026-48779: ws 8.18.3 → 5.2.5, 6.2.4, 7.5.11, 8.21.0 — ws is an open source WebSocket client and server for Node.js. All vers ...

services/admin-service/Gemfile.lock

  • CRITICAL CVE-2026-33202: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — rails: Active Storage: Unintended file deletion via crafted blob keys
  • HIGH CVE-2026-33174: activestorage 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Storage: Rails Active Storage: Denial of Service via unbounded Range header
  • HIGH CVE-2026-33176: activesupport 7.1.6 → ~> 7.2.3, >= 7.2.3.1, ~> 8.0.4, >= 8.0.4.1, >= 8.1.2.1 — Rails: Active Support: Activ

Next steps

  • Review the findings manually
  • Check if the fixes require breaking API changes
  • Consider adding justified suppressions to .trivyignore
    with proper documentation

Opened automatically by the SAST auto-remediation pipeline.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions