Skip to content

fix: address new braces/http-cache-semantics/node-forge security advisories - #9887

Merged
rishikeshdadam136 merged 1 commit into
masterfrom
chore/osv-exclude-nov2026-criticals
Oct 3, 2026
Merged

rishikeshdadam136 merged 1 commit into
masterfrom
chore/osv-exclude-nov2026-criticals

Conversation

@rishikeshdadam136

@rishikeshdadam136 rishikeshdadam136 commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Excludes three unpatched CVSS 8.7 advisories from the osv-scanner release gate; no upstream fix is available for any of them yet.

  • GHSA-vfj7-8cjw-p6xm (braces, CVE-2026-93687): stack-overflow DoS; dev tooling only (chokidar/karma/lint-staged), code-controlled globs.
  • GHSA-ch52-4w7c-c8xp (http-cache-semantics, CVE-2026-93748): shared-cache response confusion; our usages are single-process client caches, not a shared/proxy cache.
  • GHSA-86w9-cpqp-85rv (node-forge, CVE-2026-85393): RSA PKCS#1 v1.5 signature-forgery; dev-only via selfsigned in @cypress/webpack-dev-server, not used in any production signature-verification path.

Each entry carries a 2026-12-03 re-evaluation note so the exclusions can be dropped as soon as upstream patches ship.

TICKET: WCI-1724

…sories

Excludes three unpatched CVSS 8.7 advisories from the osv-scanner release
gate; no upstream fix is available for any of them yet.

- GHSA-vfj7-8cjw-p6xm (braces, CVE-2026-93687): stack-overflow DoS; dev
  tooling only (chokidar/karma/lint-staged), code-controlled globs.
- GHSA-ch52-4w7c-c8xp (http-cache-semantics, CVE-2026-93748): shared-cache
  response confusion; our usages are single-process client caches, not a
  shared/proxy cache.
- GHSA-86w9-cpqp-85rv (node-forge, CVE-2026-85393): RSA PKCS#1 v1.5
  signature-forgery; dev-only via selfsigned in @cypress/webpack-dev-server,
  not used in any production signature-verification path.

Each entry carries a 2026-12-03 re-evaluation note so the exclusions can
be dropped as soon as upstream patches ship.

TICKET: WCI-1724
@rishikeshdadam136 rishikeshdadam136 changed the title fix: address new braces/http-cache-semantics/node-forge security advi… fix: address new braces/http-cache-semantics/node-forge security advisories Oct 3, 2026
@rishikeshdadam136
rishikeshdadam136 marked this pull request as ready for review October 3, 2026 15:34
@rishikeshdadam136
rishikeshdadam136 requested review from a team as code owners October 3, 2026 15:34
@rishikeshdadam136
rishikeshdadam136 merged commit bf799aa into master Oct 3, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants