Skip to content

Fix dependabot alerts / dependencies vulnerabilities [October 5th 2026] - #1849

Merged
davinotdavid merged 3 commits into
mainfrom
davinotdavid/fix-vulnerabilities-oct-5
Oct 5, 2026
Merged

davinotdavid merged 3 commits into
mainfrom
davinotdavid/fix-vulnerabilities-oct-5

Conversation

@davinotdavid

@davinotdavid davinotdavid commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What changed?

Bump version to 1.8.1 and updating dependencies flagged by dependabot where applicable (and there's a new package version for us to update).

Ecosystem Manifest Package Old New Severity Alerts Issue fixed
pip backend/requirements.txt, uv.lock PyJWT 2.13.0 2.15.0 critical / high / medium #320, #321, #322, #323, #324, #325, #326, #327, #328, #329, #330, #331, #335, #336, #337, #338, #339, #340, #341, #342, #343, #344, #345, #349 Asymmetric-PEM detection bypass, HMAC key confusion (DER, JWK, BOM, empty keys), PyJWKClient redirects and JWKS amplification, ReDoS, RecursionError DoS, signature canonicalization
pip backend/requirements.txt, uv.lock oauthlib 3.3.1 4.0.0 medium #309, #333, #334 PKCE code_verifier timing attack, JSONP callback injection in RevocationEndpoint
pip backend/uv.lock tornado 6.5.8 6.5.10 high / medium #350, #351, #352 StaticFileHandler symlink path traversal, CurlAsyncHTTPClient decompression bomb, unbounded query-string args DoS
pip backend/uv.lock urllib3 2.7.0 2.8.0 high / medium #346, #347, #348 HTTPS proxy TLS config ignored, unbounded chunk-size buffering, chunked deflate infinite loop
npm frontend/pnpm-lock.yaml brace-expansion 1.1.18 / 2.1.4 / 5.0.9 1.1.21 / 2.1.7 / 5.0.12 high / medium #355, #358, #360, #361, #362 Recursion stack exhaustion DoS, quadratic-time expansion DoS
npm frontend/pnpm-lock.yaml dompurify 3.4.13 3.4.16 low #363 IN_PLACE afterSanitize hook leaves detached subtree handlers armed (DOM XSS)
npm frontend/pnpm-lock.yaml undici 8.10.0 8.11.2 high / medium / low #310, #312, #313, #314, #315, #317, #318 Cache poisoning, TLS validation bypass in BalancedPool, Set-Cookie cache disclosure, retry/dump interceptor issues
npm test/e2e/pnpm-lock.yaml brace-expansion 2.1.1 2.1.7 high / medium #263, #368 Exponential and quadratic expansion DoS
npm test/e2e/pnpm-lock.yaml fast-uri 3.1.2 3.1.8 high #267, #268, #285, #295, #299, #300, #365 Host confusion (IDN, backslash, percent-encoded scheme), SSRF via IPv6/hostname decoding, port injection
npm test/e2e/pnpm-lock.yaml ip-address 10.2.0 10.7.3 high / medium #273, #274, #283, #307, #364, #370 SSRF / trust-boundary bypasses (IPv4-mapped, NAT64, leading-zero octets, CIDR suffix, link-local, family mixing)
npm test/e2e/pnpm-lock.yaml http-cache-semantics 4.2.0 4.3.0 high #376 max-stale handling discloses cross-user cached responses
npm test/e2e/pnpm-lock.yaml @grpc/grpc-js 1.14.5 1.14.5 (floor ^1.13.6) high / low #372, #373 Unauthorized certs in getAuthContext, error message leakage (installed version already patched)
npm test/e2e/pnpm-lock.yaml protobufjs 7.5.8 7.6.6 high / moderate none (found by pnpm audit) Fixed in 7.6.1, 7.6.3 and 7.6.5
npm test/e2e/pnpm-lock.yaml qs 6.15.2 6.16.0 moderate none (found by pnpm audit) Fixed in 6.15.4 and 6.16.0
npm test/e2e/pnpm-lock.yaml basic-ftp 5.3.1 6.2.2 high none (found by pnpm audit) Fixed in 6.2.1

Wrote the table with the help of Claude code, otherwise vulnerabilities were found / patched by pnpm audit.

Why?

New day, new dependabot alerts for vulnerabilities.

Limitations and Notes

  • There's a major bump in oauthlib but the breaking changes listed in the repo doesn't affect us and we don't event import it directly anywhere. The paths that would be affected would be the ZoomClient and GoogleClient and both seem to work as expected.

  • Note that I've had to narrowly-er specify the sqlalchemy pinned version in requirements.txt to be 2.0.* instead of 2.* since there was a breaking change (ScalarAttributeImpl) from 2.1.* and a fresh install of all the packages would fail to build and run the backend container.

  • Also, there are some vulnerabilities that are not yet patched:

- braces (#375, frontend, high): the latest published version is 3.0.3, which is still vulnerable.
- aws-sdk (#256, e2e, low): v2 has no patched release. It comes in through browserstack-node-sdk.
- PyJWT #353 and #332: these list no patched version. 2.15.0 is the latest release.

Applicable Issues

N/A

QA Log

Manually ran the project locally and went through FTUE + created a booking through a Google Calendar integration.

Screenshots

N/A

@rwood-moz rwood-moz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM and I see all the checks passed.

@davinotdavid
davinotdavid merged commit f62bac6 into main Oct 5, 2026
10 checks passed
@davinotdavid
davinotdavid deleted the davinotdavid/fix-vulnerabilities-oct-5 branch October 5, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants