Skip to content

Update Socket patches: +12 patches - #731

Closed
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551742918-de1c32b5
Closed

Update Socket patches: +12 patches#731
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551742918-de1c32b5

Conversation

@socket-security

Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2026-32141 in pkg:npm/flatted@3.3.3 (Socket Patch)
    • Severity: HIGH
    • Summary: flatted vulnerable to unbounded recursion DoS in parse() revive phase
  • Added: CVE-2026-6322 in pkg:npm/fast-uri@3.1.0 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to host confusion via percent-encoded authority delimiters
  • Added: CVE-2026-48779 in pkg:npm/ws@8.19.0 (Socket Patch)
    • Severity: HIGH
    • Summary: ws: Memory exhaustion DoS from tiny fragments and data chunks
  • Added: CVE-2026-6321 in pkg:npm/fast-uri@3.1.0 (Socket Patch)
    • Severity: HIGH
    • Summary: fast-uri vulnerable to path traversal via percent-encoded dot segments
  • Added: CVE-2026-26996 in pkg:npm/minimatch@3.1.2 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
  • Added: CVE-2026-26996 in pkg:npm/minimatch@9.0.5 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
  • Added: CVE-2026-33671 in pkg:npm/picomatch@4.0.3 (Socket Patch)
    • Severity: HIGH
    • Summary: Picomatch has a ReDoS vulnerability via extglob quantifiers
  • Added: CVE-2026-33671 in pkg:npm/picomatch@2.3.1 (Socket Patch)
    • Severity: HIGH
    • Summary: Picomatch has a ReDoS vulnerability via extglob quantifiers
  • Added: in pkg:npm/serialize-javascript@6.0.2 (Socket Patch)
    • Severity: HIGH
    • Summary: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
  • Added: in pkg:npm/serialize-javascript@4.0.0 (Socket Patch)
    • Severity: HIGH
    • Summary: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
  • Added: CVE-2026-9277 in pkg:npm/shell-quote@1.8.3 (Socket Patch)
    • Severity: CRITICAL
    • Summary: shell-quote quote() does not escape newlines in object .op values
  • Added: CVE-2026-29074 in pkg:npm/svgo@4.0.0 (Socket Patch)
    • Severity: HIGH
    • Summary: SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 22 blob(s) added
- 0 blob(s) removed
- Manifest updated
@changeset-bot

changeset-bot Bot commented Aug 12, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: dda3453

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@codecov

codecov Bot commented Aug 12, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.29%. Comparing base (23adc7a) to head (dda3453).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #731   +/-   ##
=======================================
  Coverage   76.29%   76.29%           
=======================================
  Files          17       17           
  Lines         983      983           
  Branches      358      358           
=======================================
  Hits          750      750           
  Misses        206      206           
  Partials       27       27           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@valscion

Copy link
Copy Markdown
Collaborator

What is this? We have a dev-only tool here so lots of these CVE's are not applicable to this library. I don't want to ship some 18k+ diff without knowing why this thing even appears here in the first place and why it would be useful.

@avivkeller avivkeller closed this Aug 13, 2026
@avivkeller

Copy link
Copy Markdown
Member

This is part of an ongoing security improvement by the technical steering committee. Not sure why Socket didn't bump the deps directly, but expect a corrected PR in due time

@valscion

Copy link
Copy Markdown
Collaborator

OK thanks!

@valscion
valscion deleted the socket/autopatch-1786551742918-de1c32b5 branch August 13, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants