Skip to content

CVE fix for CVE-2025-64718 and CVE-2024-11831 - #1926

Merged
SuZhou-Joe merged 2 commits into
opensearch-project:2.19from
yubonluo:cve-fix-2.19
Mar 2, 2026
Merged

CVE fix for CVE-2025-64718 and CVE-2024-11831#1926
SuZhou-Joe merged 2 commits into
opensearch-project:2.19from
yubonluo:cve-fix-2.19

Conversation

@yubonluo

Copy link
Copy Markdown
Collaborator

Description

Fix two CVE: CVE-2025-64718 and CVE-2024-11831

Bump serialize-javascript version to greater than 6.0.2 to avoid XSS
Bump js-yaml and mocha

Reference:

Issues Resolved

[List any issues this PR will resolve]

Check List

  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: yubonluo <yubonluo@amazon.com>
SuZhou-Joe
SuZhou-Joe previously approved these changes Feb 26, 2026
@SuZhou-Joe

Copy link
Copy Markdown
Member
image Seems mocha upgrade is breaking some CI.

Signed-off-by: yubonluo <yubonluo@amazon.com>
@yubonluo
yubonluo force-pushed the cve-fix-2.19 branch 2 times, most recently from 6745e6d to de0de4c Compare February 26, 2026 13:18
@yubonluo

yubonluo commented Feb 26, 2026

Copy link
Copy Markdown
Collaborator Author

image Seems mocha upgrade is breaking some CI.

This doesn't seem to be related to my commit. Even if I reverse the mocha commit, CI still fails

@yubonluo
yubonluo force-pushed the cve-fix-2.19 branch 2 times, most recently from 461e961 to e7953b6 Compare February 26, 2026 14:38
@SuZhou-Joe
SuZhou-Joe merged commit cb54a42 into opensearch-project:2.19 Mar 2, 2026
102 of 119 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants