Skip to content

Conversation

@aikido-autofix
Copy link

This PR will resolve the following CVEs:

CVE ID Severity Description
AIKIDO-2025-10094
MEDIUM
Affected versions of this package improperly handle user-controlled input when parsing headers for /graphql endpoints or URL objects in general. This can lead to excessive backtracking in regular expressions, making the application vulnerable to Regular expression Denial of Service (ReDoS). Attack...
CVE-2025-25288
LOW
@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package @octokit/plugin-paginate-rest, when calling octokit.paginate.iterator(), a specially crafted octokit instance—particularly with a m
CVE-2025-25290
LOW
@octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to version 9.2.1, the regular expression /<([^>]+)>; rel="deprecation"/ used to match the link header in HTTP responses is vulnerable to a ReDoS (Regula
CVE-2025-25289
LOW
@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant