-
Notifications
You must be signed in to change notification settings - Fork 51
Open
Description
Hello,
I noticed that @cosmology/lcd depends on a vulnerable version of axios (1.0.0 - 1.11.0) which has a high severity security issue.
Vulnerability details:
- DoS attack through lack of data size check
- Advisory: GHSA-4hjh-wcwx-xvwj
Current situation:
@cosmology/lcd >=0.13.2depends on vulnerable versions of axios- We're currently using
@cosmology/lcd@^0.15.0
Request:
Could you update @cosmology/lcd to use a secure version of axios (>= 1.12.0)?
npm audit output:
axios 1.0.0 - 1.11.0
Severity: high
Axios is vulnerable to DoS attack through lack of data size check
node_modules/axios
@cosmology/lcd >=0.13.2
Depends on vulnerable versions of axios
Thanks!
Metadata
Metadata
Assignees
Labels
No labels