fix: upgrade undici to patched version (CVE-2026-12151) - #81
Closed
anupamme wants to merge 1 commit into
Closed
Conversation
Automated dependency upgrade by OrbisAI Security
MikeGibbsOnyx
approved these changes
Sep 6, 2026
MikeGibbsOnyx
left a comment
Collaborator
There was a problem hiding this comment.
Verified locally on Node v22.23.2: npm ci; 190/190 tests pass; TypeScript check passes; production Vite build passes. npm audit --omit=dev no longer reports an undici advisory (remaining qs advisory is unrelated).
MikeGibbsOnyx
added a commit
that referenced
this pull request
Sep 8, 2026
Collaborator
|
Superseded: content landed on main via the 2026-09-08 backlog integration (main tip 950ac31, full suite 312/312 green). Credit preserved in the merge history. |
plana-ai-agent
added a commit
to plana-ai-agent/sparkDash
that referenced
this pull request
Sep 8, 2026
Upstream range: cc44d35..1573e76 Imported highlights: - PR MiaAI-Lab#1-MiaAI-Lab#6 audit remediation merges (secure dashboard administration, durable registry, bounded live telemetry, fleet operations UX, secure installation, audit validation) - Fleet energy telemetry (PR MiaAI-Lab#63), LLM trend chart (PR MiaAI-Lab#75), q27 LLM backend telemetry (PR MiaAI-Lab#74) - LLM API key reconciliation (PR MiaAI-Lab#76), worker derived labels (PR MiaAI-Lab#79), undici security update (PR MiaAI-Lab#81) - SSH transport reuse (PR MiaAI-Lab#77), monitor polling lifecycle isolation (PR MiaAI-Lab#59) - llmTunnel.js new remote LLM tunnel collector, per-node LLM runtime settings - hideWorkers setting, overview search/status filters (default off), remote bind/preflight - Bench/PrefillBench/DecodeBench streaming resource fixes, websocket snapshot fix Fork features preserved: GPU ECO (server/eco.js, EcoControl.tsx), Local LLM Runtime (server/localLlmSwitch.js, LocalLlmControl.tsx), worker SSH key auth in docker-compose.yml # Conflicts: # .env.example # README.md # docker-compose.yml # package.json # server/settings.js # src/components/OverviewPage/OverviewPage.tsx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrade undici from 6.24.1 to 6.27.0, 7.28.0, 8.5.0 to fix CVE-2026-12151.
Vulnerability
CVE-2026-12151package-lock.json(dependency:undici)Description: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
Evidence
Scanner confirmation: trivy rule
CVE-2026-12151flagged this pattern.Changes
package.jsonpackage-lock.jsonBehavior Preservation
This change touches only dependency manifests (
package.json,package-lock.json); no source file in the repository is modified.This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.
Automated security fix by OrbisAI Security