Commit a8b5670
committed
Bump undici for CVEs
undici <=6.26.0
Severity: high
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding - GHSA-p88m-4jfj-68fv
undici WebSocket client vulnerable to denial of service via fragment count bypass - GHSA-vxpw-j846-p89q
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse - GHSA-35p6-xmwp-9g52
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching - GHSA-g8m3-5g58-fq7m
Signed-off-by: Jason Frey <fryguy9@gmail.com>1 parent e404618 commit a8b5670
3 files changed
Lines changed: 6 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments