Skip to content

Conversation

aikido-autofix[bot]
Copy link
Contributor

@aikido-autofix aikido-autofix bot commented Jul 3, 2025

This PR will resolve the following CVEs:

CVE ID Severity Description
AIKIDO-2024-10065
MEDIUM
Affected versions of the undici library are vulnerable to memory leaks. By making multiple fetch requests with the same AbortSignal, undici adds event listeners without removing them, leading to excessive memory consumption.
AIKIDO-2025-10024
MEDIUM
Affected versions of the undici library are vulnerable because they use insufficiently random values generated by Math.random() when encoding form-data in the body. Since Math.random() produces low-entropy and predictable values, attackers could potentially exploit this flaw to manipulate or a...

Copy link

codecov bot commented Jul 3, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

📢 Thoughts on this report? Let us know!

@aikido-autofix aikido-autofix bot closed this Jul 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants