Skip to content

fix(deps): vuln minor: ip-address · patch: brace-expansion [package.json] - #737

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/1-1791201747
Open

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/1-1791201747

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 4 packages upgraded (MINOR changes included)

Manifests changed:

  • package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
brace-expansion 5.0.9 5.0.12 patch Transitive 4 HIGH, 2 MEDIUM
brace-expansion 2.1.4 2.1.7 patch Transitive 4 HIGH, 2 MEDIUM
brace-expansion 1.1.18 1.1.21 patch Transitive 4 HIGH, 2 MEDIUM
ip-address 10.4.0 10.7.3 minor Transitive 8 MEDIUM

Security Details

🚨 Critical & High Severity (12 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 2.1.4 5.0.11 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 2.1.4 - -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 - -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 5.0.11 -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 - -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 5.0.9 - -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 5.0.9 5.0.10 -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 2.1.4 - -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 5.0.9 5.0.11 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 5.0.9 - -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 2.1.4 5.0.10 -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 5.0.10 -
ℹ️ Other Vulnerabilities (14)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 - -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 5.0.12 -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 2.1.4 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 2.1.4 - -
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 5.0.9 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 5.0.9 - -
ip-address CVE-2026-101911 MODERATE ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process 10.4.0 - -
ip-address GHSA-rpw4-54j3-4h4q MODERATE ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts 10.4.0 10.5.1 -
ip-address CVE-2026-101910 MODERATE ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass 10.4.0 - -
ip-address GHSA-2vr4-cq9g-pvrc MODERATE ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass 10.4.0 10.5.1 -
ip-address CVE-2026-101912 MODERATE ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range 10.4.0 - -
ip-address GHSA-j6r3-76f7-8jcv MODERATE ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range 10.4.0 10.7.1 -
ip-address CVE-2026-101913 MODERATE ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts 10.4.0 - -
ip-address GHSA-h3mg-xc3c-68pw MODERATE ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process 10.4.0 10.7.1 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with main — rebased onto 912549b.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-aad58d
dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/minorpatch/npm/1-1791201747 branch from 9c5d0c5 to 4425ee2 Compare October 5, 2026 14:11
@dd-octo-sts
dd-octo-sts Bot marked this pull request as ready for review October 7, 2026 19:20
@dd-octo-sts
dd-octo-sts Bot requested a review from a team as a code owner October 7, 2026 19:20
@dd-octo-sts
dd-octo-sts Bot requested a review from avangelillo October 7, 2026 19:20
@dd-prapprover-prod-77c48c

dd-prapprover-prod-77c48c Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

PRApprover will approve and merge this PR, FAQ, #dx-source-code-management

🛠️ PRApproval Status

  • ✅ PR is eligible for auto-approval by rule dependency-management-version-updater - 2026-10-07T19:21:16Z
  • ⬜ CI tests passed
  • ⬜ Approved
  • ⬜ Merge Started
  • ⬜ Merged

➡️ Current phase: waiting for CI tests to complete...

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants