fix(security): fix 15 security issues in axios, undici - #269
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
3 tasks
✅ Security Analysis ResultsNo security issues found. 2 files reviewed.
|
Author
|
Aikido's automated cron job opened a newer AutoFix. It fixes the same vulnerabilities and more: fix(security): fix 16 security issues in axios, undici |
aikido-autofix
Bot
deleted the
fix/aikido-security-update-packages-120054510-kbpp
branch
September 27, 2026 03:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Jira ticket: https://typeform.atlassian.net/browse/<TICKET_ID>
Upgrade axios and undici to fix SSRF/proxy bypass, prototype pollution header injection, credential leakage on cross-origin redirects, and unsafe error serialization vulnerabilities.
Changes
🤖 Remediation details
Fix security vulnerabilities in
axiosandundicitransitive dependenciesShort summary
This PR remediates high- and medium-severity vulnerabilities in two transitive dependencies —
axiosandundici— pulled in undershared-actions/send-deployment-event. The fix touchesshared-actions/send-deployment-event/package.json(a newresolutionsfield foraxios) andshared-actions/send-deployment-event/yarn.lock(resolved versions updated for both packages).axios
axiosis a transitive dependency introduced by the direct dependencyanalytics-node@6.2.0, which pinsaxios@^0.27.2. The installed version0.27.2is affected by multiple vulnerabilities requiring a minimum of1.18.0to fully remediate. Becauseanalytics-node@6.2.0is the latest published release and still declaresaxios@^0.27.2— with no newer version ofanalytics-nodeavailable that upgrades to a patchedaxios— there is no viable parent-bump path. Aresolutionsentry of"axios": "1.18.0"was added topackage.jsonas a last resort, forcing the lockfile to resolveaxiosat1.18.0regardless of the range declared byanalytics-node.undici
undiciis a transitive dependency introduced by@actions/http-client@4.0.0, which is itself pulled in by the direct dependency@actions/core@3.0.1. The installed version6.24.1is affected by multiple vulnerabilities requiring a minimum of6.28.1. The parent@actions/http-client@4.0.0already declaresundici@^6.23.0, a range that permits6.28.1, so no manifest change was needed — a lockfile refresh viayarn upgrade 'undici@^6.23.0'was sufficient to resolve the package to6.28.1.Version changes
axios0.27.21.18.0resolutions(no viable parent-bump path throughanalytics-node@6.2.0)undici6.24.16.28.1^6.23.0already admitted patched version)Testing
Docs
Security Impact — CVE vulnerabilities fixed by this PR
✅ 15 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
X-API-Key) during cross-origin redirects, potentially leaking API keys and authentication tokens to unintended hosts. This information disclosure vulnerability affects shared environments where secret headers are set by default.allowAbsoluteUrlsnot being set tofalseby default inbuildFullPath(), allowing attackers to bypass URL restrictions and process unintended URLs.//(e.g.,https:internal.example), allowing attackers to bypass URL allowlists or WAF checks and reach unintended hosts. The vulnerability enables URL validation bypass through silent normalization of invalid URLs.formDataToJSONfunction allows attackers to modify object prototypes. Additionally, a ReDoS vulnerability incombineURLscan cause denial of service through malicious input.Breaking Changes & Upgrade Impact
✅ Code not affected by breaking changes.
✅ No breaking changes from either axios or undici affect this codebase.
axios (0.27.2 => 1.18.0):
The axios 1.8.0 breaking change regarding URL combining with
baseURLdoes not affect this code. The codebase usesaxios.create(options.axiosConfig)without setting abaseURL, and always callsaxiosInstance.post()with a complete URL (${this.host}${this.path}), not a relative URL that would trigger URL combination logic.undici (6.24.1 => 6.28.1):
None of the undici breaking changes affect this codebase. The package uses undici only as a transitive dependency through
@actions/http-client, and the codebase doesn't directly use any of the affected undici features:No WebSocket usage in the codebase
No
parseSetCookieorsetCookiecallsNo direct manipulation of cookies or Content-Range headers
No custom blob-like request bodies
All breaking changes by upgrading axios from version 0.27.2 to 1.18.0 (CHANGELOG)
All breaking changes by upgrading undici from version 6.24.1 to 6.28.1 (CHANGELOG)
parseSetCookieno longer applies percent-decoding to cookie values, changing behavior for cookies containing encoded sequences like%0D%0Aand%00SameSitevalues (Strict,Lax,None) rather than accepting them as substrings, rejecting previously accepted values likeSameSite=NoneOfYourBusinessContent-Lengthis inconsistent withContent-Range, where previously inconsistent responses may have been acceptedsetCookie()now applies stricter validation that may reject previously accepted unsanitized domain and unparsed valuestypeproperties on duck-typed blob-like HTTP/1.1 request bodies are now coerced and validated, potentially rejecting previously accepted valuesFor contributions to the
Typeform/.githubrepoNote: Please do not use this repository for new internal shared workflows and actions. Use https://github.com/Typeform/.github-private instead!
Please check that your contribution applies to one of these cases below. If this is not the case, please contribute to https://github.com/Typeform/.github-private instead.