Skip to content

Security fixes ethena labs - #124

Merged
deHB6 merged 3 commits into
ethena-labs:mainfrom
ElliotWood13:security-fixes-ethena-labs
Dec 12, 2025
Merged

Security fixes ethena labs#124
deHB6 merged 3 commits into
ethena-labs:mainfrom
ElliotWood13:security-fixes-ethena-labs

Conversation

@ElliotWood13

Copy link
Copy Markdown
Contributor

No description provided.

- Upgrade form-data from 4.0.1 to 4.0.5 (CVE-2025-7783)
- Upgrade base-x from 3.0.10/5.0.0 to 3.0.11/5.0.1 (homograph attack)
- Replace bigint-buffer with bigint-buffer-fixed (buffer overflow)
- Upgrade axios from 1.7.9/0.25.0 to 1.12.0+ (DoS and CSRF)
- Upgrade @babel/runtime and @babel/core to 7.26.10+ (RegExp complexity)
- Upgrade brace-expansion from 1.1.11 to 1.1.12 (ReDoS)
- Upgrade js-yaml from 3.14.1 to 3.14.2 (prototype pollution)
- Added constants for affluent integration start blocks in campaign.py.
- Updated error messages in affluent_integration.py and evaa_integration.py to clarify payload issues.
- Fixed string formatting in logging statements in strata_jrusde.py and strata_srusde.py.
@ElliotWood13
ElliotWood13 marked this pull request as ready for review December 12, 2025 14:23
@ElliotWood13
ElliotWood13 requested a review from a team as a code owner December 12, 2025 14:23
@deHB6
deHB6 merged commit 049ab07 into ethena-labs:main Dec 12, 2025
1 check failed
@ElliotWood13
ElliotWood13 deleted the security-fixes-ethena-labs branch December 12, 2025 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants