Skip to content

fix(deps): vuln axios (minor → 1.20.0) [integration_tests/container/cjs/package.json] - #844

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/container/0-1791183713
Draft

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/container/0-1791183713

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • integration_tests/container/cjs/package.json (npm)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
axios 1.18.1 1.20.0 minor Direct 14 HIGH, 9 MEDIUM

Security Details

🚨 Critical & High Severity (14 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
axios CVE-2026-101906 HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.1 - -
axios GHSA-c29m-xwm3-cm6r HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.1 1.20.0 -
axios CVE-2026-101898 HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.1 - -
axios GHSA-3pq3-5fj3-cg6v HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.1 1.20.0 -
axios GHSA-m8m8-qj5v-23w3 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.1 1.20.0 -
axios CVE-2026-101905 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.1 - -
axios GHSA-542g-h47m-68v8 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.1 1.20.0 -
axios GHSA-x97p-jq2g-jp4f HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.1 0.34.0 -
axios CVE-2026-101907 HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.1 - -
axios CVE-2026-101903 HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.1 - -
axios GHSA-r4gj-5m52-g5wh HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.1 1.20.0 -
axios GHSA-mghh-pgcx-3jjj HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.1 1.20.0 -
axios CVE-2026-101901 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.1 - -
axios CVE-2026-101909 HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.1 - -
ℹ️ Other Vulnerabilities (9)
Package CVE Severity Summary Unsafe Version Fixed In Case
axios GHSA-vh66-26gq-q6x8 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.1 1.20.0 -
axios GHSA-j8rh-479h-cp32 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.1 1.20.0 -
axios CVE-2026-101904 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.1 - -
axios CVE-2026-101908 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.1 - -
axios GHSA-44g4-m2mj-wpvx MODERATE Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges 1.18.1 1.20.0 -
axios CVE-2026-101900 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.1 - -
axios GHSA-4hqw-qxg8-jxx2 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.1 1.20.0 -
axios GHSA-9fr6-4gfg-395g MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.1 0.34.0 -
axios CVE-2026-101902 MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.1 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-datadog-prod-us1

datadog-datadog-prod-us1 Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Pipelines

✨ Unblock PR with BitsAI

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 10 Pipeline jobs failed

local integration tests | nodejs18.x (amd64) — 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

local integration tests | nodejs18.x (arm64) — 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

local integration tests | nodejs20.x (arm64) — 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

View all 10 failed jobs.

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c9d34c8 | Docs | View more details | Give us feedback!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants