Skip to content

fix(security): fix 15 security issues in axios, undici - #269

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-120054510-kbpp
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-120054510-kbpp

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Overview

Jira ticket: https://typeform.atlassian.net/browse/<TICKET_ID>

Upgrade axios and undici to fix SSRF/proxy bypass, prototype pollution header injection, credential leakage on cross-origin redirects, and unsafe error serialization vulnerabilities.

Changes

🤖 Remediation details

Fix security vulnerabilities in axios and undici transitive dependencies

Short summary

This PR remediates high- and medium-severity vulnerabilities in two transitive dependencies — axios and undici — pulled in under shared-actions/send-deployment-event. The fix touches shared-actions/send-deployment-event/package.json (a new resolutions field for axios) and shared-actions/send-deployment-event/yarn.lock (resolved versions updated for both packages).

axios

axios is a transitive dependency introduced by the direct dependency analytics-node@6.2.0, which pins axios@^0.27.2. The installed version 0.27.2 is affected by multiple vulnerabilities requiring a minimum of 1.18.0 to fully remediate. Because analytics-node@6.2.0 is the latest published release and still declares axios@^0.27.2 — with no newer version of analytics-node available that upgrades to a patched axios — there is no viable parent-bump path. A resolutions entry of "axios": "1.18.0" was added to package.json as a last resort, forcing the lockfile to resolve axios at 1.18.0 regardless of the range declared by analytics-node.

undici

undici is a transitive dependency introduced by @actions/http-client@4.0.0, which is itself pulled in by the direct dependency @actions/core@3.0.1. The installed version 6.24.1 is affected by multiple vulnerabilities requiring a minimum of 6.28.1. The parent @actions/http-client@4.0.0 already declares undici@^6.23.0, a range that permits 6.28.1, so no manifest change was needed — a lockfile refresh via yarn upgrade 'undici@^6.23.0' was sufficient to resolve the package to 6.28.1.

Version changes

Package From To Why updated
axios 0.27.2 1.18.0 Transitive CVE fix via resolutions (no viable parent-bump path through analytics-node@6.2.0)
undici 6.24.1 6.28.1 Transitive CVE fix — lockfile refresh only (parent range ^6.23.0 already admitted patched version)

Testing

Docs

  • Yes! ✋ I have updated the documentation.

Security Impact — CVE vulnerabilities fixed by this PR

✅ 15 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-62718
HIGH
[axios] Improper hostname normalization in NO_PROXY rule checking allows requests to loopback addresses (localhost., [::1]) to bypass proxy protections, enabling proxy bypass and potential SSRF attacks against internal services. This vulnerability permits attackers to reach sensitive services despite configured NO_PROXY protections.
AIKIDO-2026-10741
HIGH
[axios] HTTP client vulnerability allowing prototype pollution through loose object merging, sensitive data exposure via error serialization, and improper proxy/socket handling that could lead to information disclosure or unauthorized access.
CVE-2026-40175
HIGH
[axios] A prototype pollution vulnerability in a third-party dependency can be exploited to inject unsanitized header values into outbound HTTP requests. This could allow attackers to manipulate request headers for potential information disclosure or request forgery attacks.
AIKIDO-2026-291630
HIGH
[axios] HTTP adapter fails to strip custom credential headers (like X-API-Key) during cross-origin redirects, potentially leaking API keys and authentication tokens to unintended hosts. This information disclosure vulnerability affects shared environments where secret headers are set by default.
AIKIDO-2026-10509
HIGH
[axios] Prototype pollution vulnerability allows attackers to inject malicious headers into requests through unsafe FormData detection and header merging, potentially enabling authorization bypass or request manipulation.
CVE-2023-45857
MEDIUM
[axios] An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
CVE-2026-25639
MEDIUM
[axios] The mergeConfig function crashes with a TypeError when processing configuration objects containing proto as an own property, allowing attackers to trigger denial of service. An attacker can exploit this by providing a malicious configuration object created via JSON.parse().
AIKIDO-2025-10185
MEDIUM
[axios] A server-side request forgery (SSRF) vulnerability exists due to allowAbsoluteUrls not being set to false by default in buildFullPath(), allowing attackers to bypass URL restrictions and process unintended URLs.
AIKIDO-2026-38469
MEDIUM
[axios] Accepts malformed HTTP/HTTPS URLs without // (e.g., https:internal.example), allowing attackers to bypass URL allowlists or WAF checks and reach unintended hosts. The vulnerability enables URL validation bypass through silent normalization of invalid URLs.
CVE-2025-27152
MEDIUM
[axios] Axios sends requests to absolute URLs even when baseURL is configured, bypassing intended routing and potentially causing Server-Side Request Forgery (SSRF) and credential leakage in both server and client environments.
AIKIDO-2023-10001
LOW
[axios] Prototype pollution vulnerability in the formDataToJSON function allows attackers to modify object prototypes. Additionally, a ReDoS vulnerability in combineURLs can cause denial of service through malicious input.
AIKIDO-2026-145478
HIGH
[undici] WebSocket client fails to limit the number of message fragments, allowing a malicious server to send unlimited continuation frames that bypass payload size checks and cause unbounded memory growth, leading to denial of service.
AIKIDO-2026-775839
HIGH
[undici] WebSocket client crashes with an uncaught TypeError when receiving an unrequested Sec-WebSocket-Protocol header in a 101 response, causing process termination. The vulnerability allows remote servers to trigger a Denial of Service by sending unexpected subprotocol headers during the handshake.
AIKIDO-2026-48713
MEDIUM
[undici] The Set-Cookie parser incorrectly percent-decodes cookie values, allowing encoded sequences like %0D%0A to become literal bytes. This enables HTTP response header injection attacks (session fixation, open redirect, cache poisoning) when parsed values are forwarded to response headers.
AIKIDO-2026-253444
LOW
[undici] The retry interceptor can append resumed response bytes to a body already delivered, causing the actual body to exceed the Content-Length header. This allows excess bytes to be interpreted as a separate HTTP response by downstream peers, enabling HTTP response smuggling attacks.

Breaking Changes & Upgrade Impact

✅ Code not affected by breaking changes.

✅ No breaking changes from either axios or undici affect this codebase.

axios (0.27.2 => 1.18.0):

The axios 1.8.0 breaking change regarding URL combining with baseURL does not affect this code. The codebase uses axios.create(options.axiosConfig) without setting a baseURL, and always calls axiosInstance.post() with a complete URL (${this.host}${this.path}), not a relative URL that would trigger URL combination logic.

undici (6.24.1 => 6.28.1):

None of the undici breaking changes affect this codebase. The package uses undici only as a transitive dependency through @actions/http-client, and the codebase doesn't directly use any of the affected undici features:

  • No WebSocket usage in the codebase

  • No parseSetCookie or setCookie calls

  • No direct manipulation of cookies or Content-Range headers

  • No custom blob-like request bodies

All breaking changes by upgrading axios from version 0.27.2 to 1.18.0 (CHANGELOG)

Version Description
1.8.0
code relying on the above will now combine the URLs instead of prefer request URL
1.0.0
There are multiple deprecations, refactors and fixes provided in this release. Please read through the full release notes to see how this may impact your project and use case.

All breaking changes by upgrading undici from version 6.24.1 to 6.28.1 (CHANGELOG)

Version Description
6.27.0
WebSocket fragment count limit enforced - applications using WebSocket against untrusted endpoints will now reject messages with excessive fragment counts that previously would have been accepted (though this caused DoS)
6.27.0
Set-Cookie percent-decoding removed - parseSetCookie no longer applies percent-decoding to cookie values, changing behavior for cookies containing encoded sequences like %0D%0A and %00
6.27.0
SameSite attribute parsing strictness - cookie parser now requires exact matches for SameSite values (Strict, Lax, None) rather than accepting them as substrings, rejecting previously accepted values like SameSite=NoneOfYourBusiness
6.27.0
Idle socket validation changes - keep-alive socket reuse behavior modified to prevent response queue poisoning, potentially affecting applications relying on previous socket reuse timing
6.28.0
Content-Length validation on partial responses - retry interceptor now rejects partial responses whose Content-Length is inconsistent with Content-Range, where previously inconsistent responses may have been accepted
6.28.0
Cookie domain, path, and unparsed attribute validation - setCookie() now applies stricter validation that may reject previously accepted unsanitized domain and unparsed values
6.28.0
Blob-like request body type property validation - malicious or invalid type properties on duck-typed blob-like HTTP/1.1 request bodies are now coerced and validated, potentially rejecting previously accepted values

For contributions to the Typeform/.github repo

Note: Please do not use this repository for new internal shared workflows and actions. Use https://github.com/Typeform/.github-private instead!

Please check that your contribution applies to one of these cases below. If this is not the case, please contribute to https://github.com/Typeform/.github-private instead.

  • This PR only changes an existing workflow.
  • This PR adds a new workflow that is needed in a public Typeform repository.

@pr-auditor

pr-auditor Bot commented Sep 21, 2026

Copy link
Copy Markdown

✅ Security Analysis Results

No security issues found. 2 files reviewed.


@pr-auditor rescan to re-run · Powered by Claude Sonnet 5 · Docs · #security-engineering-team

@aikido-autofix

Copy link
Copy Markdown
Author

Aikido's automated cron job opened a newer AutoFix. It fixes the same vulnerabilities and more: fix(security): fix 16 security issues in axios, undici

@aikido-autofix aikido-autofix Bot closed this Sep 27, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/aikido-security-update-packages-120054510-kbpp branch September 27, 2026 03:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants