Skip to content

Commit a8b5670

Browse files
committed
Bump undici for CVEs
undici <=6.26.0 Severity: high undici vulnerable to HTTP header injection via Set-Cookie percent-decoding - GHSA-p88m-4jfj-68fv undici WebSocket client vulnerable to denial of service via fragment count bypass - GHSA-vxpw-j846-p89q undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse - GHSA-35p6-xmwp-9g52 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching - GHSA-g8m3-5g58-fq7m Signed-off-by: Jason Frey <fryguy9@gmail.com>
1 parent e404618 commit a8b5670

3 files changed

Lines changed: 6 additions & 4 deletions

File tree

dist/index.js

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

dist/index.js.map

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package-lock.json

Lines changed: 3 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)