Skip to content

Update Socket patches: +5 patches - #45

Merged
avivkeller merged 1 commit into
mainfrom
socket/autopatch-1786551802899-f3b39852
Aug 12, 2026
Merged

Update Socket patches: +5 patches#45
avivkeller merged 1 commit into
mainfrom
socket/autopatch-1786551802899-f3b39852

Conversation

@socket-security

Copy link
Copy Markdown
Contributor

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2026-4800 in pkg:npm/lodash@4.17.23 (Socket Patch)
    • Severity: HIGH
    • Summary: lodash vulnerable to Code Injection via _.template imports key names
  • Added: CVE-2022-3517 in pkg:npm/minimatch@3.0.4 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch ReDoS vulnerability
  • Added: CVE-2021-3807 in pkg:npm/ansi-regex@5.0.0 (Socket Patch)
    • Severity: HIGH
    • Summary: Inefficient Regular Expression Complexity in chalk/ansi-regex
  • Added: CVE-2026-26996 in pkg:npm/minimatch@3.0.4 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
  • Added: CVE-2026-33671 in pkg:npm/picomatch@4.0.3 (Socket Patch)
    • Severity: HIGH
    • Summary: Picomatch has a ReDoS vulnerability via extglob quantifiers

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 7 blob(s) added
- 0 blob(s) removed
- Manifest updated
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@avivkeller
avivkeller merged commit f6d5dc1 into main Aug 12, 2026
2 of 9 checks passed
@avivkeller
avivkeller deleted the socket/autopatch-1786551802899-f3b39852 branch August 12, 2026 18:54
@avivkeller avivkeller mentioned this pull request Aug 12, 2026
avivkeller added a commit that referenced this pull request Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant