Skip to content

Conversation

@bhuvanh66
Copy link

ℹ️ Issue

Closes 83

📝 Description

Resolved the following dependabot alerts:

Multer vulnerable to Denial of Service via unhandled exception #13
https://github.com/Code-4-Community/ssf/security/dependabot/13

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
https://github.com/Code-4-Community/ssf/security/dependabot/6

Multer vulnerable to Denial of Service via memory leaks from unclosed streams #9
https://github.com/Code-4-Community/ssf/security/dependabot/9

Multer vulnerable to Denial of Service via unhandled exception from malformed request #16
https://github.com/Code-4-Community/ssf/security/dependabot/16

Multer vulnerable to Denial of Service from maliciously crafted requests #10
https://github.com/Code-4-Community/ssf/security/dependabot/10

Axios Cross-Site Request Forgery Vulnerability #2
https://github.com/Code-4-Community/ssf/security/dependabot/2

Vite allows server.fs.deny bypass via backslash on Windows #71
https://github.com/Code-4-Community/ssf/security/dependabot/71

Vite middleware may serve files starting with the same name with the public directory
https://github.com/Code-4-Community/ssf/security/dependabot/24

Vite's server.fs settings were not applied to HTML files #23
https://github.com/Code-4-Community/ssf/security/dependabot/23

node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization #76
https://github.com/Code-4-Community/ssf/security/dependabot/76

node-forge is vulnerable to ASN.1 OID Integer Truncation #77
https://github.com/Code-4-Community/ssf/security/dependabot/77

I added updates to Multer, Axios, node-forge, and Vite

✔️ Verification

Smoke tested pages after adding updates

@amywng amywng force-pushed the BH/SSF-83-fix-security-issues branch from f7e447b to e19a0d2 Compare December 2, 2025 00:22
Copy link

@dburkhart07 dburkhart07 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ☕

@bhuvanh66 bhuvanh66 merged commit 0ffb615 into main Dec 7, 2025
3 of 4 checks passed
@bhuvanh66 bhuvanh66 deleted the BH/SSF-83-fix-security-issues branch December 7, 2025 23:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants