Skip to content

fix(deps): bump fast-uri, undici and brace-expansion past their advisories - #3958

Merged
shabaraba merged 2 commits into
mainfrom
fix/cve-2026-fast-uri
Oct 1, 2026
Merged

shabaraba merged 2 commits into
mainfrom
fix/cve-2026-fast-uri

Conversation

@shabaraba

@shabaraba shabaraba commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Why

Three packages in the dependency graph are on versions with open high severity advisories.

fast-uri@4.1.3 — fixed in 4.1.4:

  • GHSA-58mr-gqgx-xq4g — parse() accepts a host with an unclosed authority bracket ([@127.0.0.1), so an application that makes a host decision from parse().host and then hands the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches.
  • GHSA-qw65-cvwx-89v3 — serialize() concatenates the port component verbatim, so a non-numeric port can inject authority delimiters and demote the intended host to userinfo.

fast-uri is not a direct dependency. It comes in through ajv, which uses it to normalize and compare $id / $ref schema identifiers. That path makes no host decisions, and the port it serializes always comes from parse(), which the second advisory calls out as unaffected. Exploitability is low; the point is to stop shipping an affected version in the lockfile.

undici@7.28.0 — fixed in 7.29.1:

  • GHSA-w293-vg96-wgc3 — TLS certificate validation bypass through connect options dropped in BalancedPool.
  • GHSA-rfgv-xxqx-mfg5 — denial of service via an unrequested WebSocket subprotocol.

Unlike the other two, this one is a runtime dependency of @kintone/rest, so it reaches consumers of the published package.

brace-expansion at 1.1.16 / 2.1.2 / 5.0.9 — fixed in 1.1.20 / 2.1.6 / 5.0.11:

What

  • fast-uri override: >=4.1.3 → >=4.1.4 <5. The lockfile resolves 4.2.1 for both ajv@8.18.0 and ajv@8.20.0. ajv still declares fast-uri: ^3.0.1 as of its latest release 8.20.0, so v4 is reached only through this override. The upper bound is there so the next major cannot be picked up unnoticed, which is how v4 was reached in the first place. Drop it once ajv declares v4 or later.
  • undici in packages/rest: 7.28.0 → 7.29.1.
  • brace-expansion overrides: ^1 → >=1.1.20 <2, ^2 → >=2.1.6 <3, ^5 → >=5.0.11 <6. The lockfile resolves 1.1.21, 2.1.7 and 5.0.12. The ^5 entry gains an upper bound so it matches the other two and cannot cross a major its consumers do not declare.
  • The minimumReleaseAgeExclude entries for fast-uri@4.1.2 and undici@7.28.0 go away. Both floors have moved past those versions, and 4.1.4 (2026-09-02) and 7.29.1 (2026-09-04) are well beyond the 24 hour hold.

This supersedes #3934, which raised the brace-expansion floors for an earlier advisory (CVE-2026-69152) to versions that the two advisories above have since overtaken. It also covers #3924, which bumps undici to 7.29.0 — one patch short of the fix.

How to test

pnpm install
pnpm build
pnpm lint
pnpm -r run test:ci

All green locally: lint, and 842 tests across the seven packages. That includes packages/rest, which is the direct undici consumer, and the 113 tests in plugin-manifest-validator, the heaviest ajv user in the repo.

Two notes on running this locally. pnpm build has to come first, otherwise lint:package fails on the missing lib/es/index.d.ts. And pnpm test:root fails here for a reason unrelated to this change — __tests__/lib/workspace.ts passes "--depth 0" to pnpm m ls as a single argument, which a recent pnpm rejects — it fails the same way on an unmodified main, so the package suites were run directly.

Checklist

  • Read CONTRIBUTING.md
  • Updated documentation if it is required.
  • Added tests if it is required.
  • Passed pnpm lint and pnpm test on the root directory.

Related PRs

The same fast-uri override change is going out to the other repositories in this org:

fast-uri 4.1.3 is affected by GHSA-58mr-gqgx-xq4g (host confusion via an
unclosed authority bracket) and GHSA-qw65-cvwx-89v3 (authority injection
via an unvalidated port in serialize). Both are fixed in 4.1.4.

fast-uri comes in through ajv, which still declares `fast-uri: ^3.0.1` as
of its latest release 8.20.0, so the override is the only lever. Cap the
range below v5 so the next major cannot be picked up unnoticed, the way
v4 was.

Drop the minimumReleaseAgeExclude entry for fast-uri@4.1.2 while here: the
floor has moved past it and 4.1.4 was published on 2026-09-02, well beyond
the 24 hour hold.
undici 7.28.0 is affected by GHSA-w293-vg96-wgc3 (TLS certificate
validation bypass through connect options dropped in BalancedPool) and
GHSA-rfgv-xxqx-mfg5 (denial of service via an unrequested WebSocket
subprotocol). Both are fixed in 7.29.1. It is a runtime dependency of
@kintone/rest, so move the pin up.

brace-expansion is affected by GHSA-6j4f-fj2g-mc7p and
GHSA-qhr7-859c-m2p7, both stack exhaustion through uncontrolled
recursion. Raise the override floors to the patched versions: 1.1.20,
2.1.6 and 5.0.11. The lockfile resolves 1.1.21, 2.1.7 and 5.0.12.

Cap the `^5` override below v6 while here, so it matches the other two
entries and cannot cross a major that its consumers do not declare.

Drop the minimumReleaseAgeExclude entry for undici@7.28.0: the pin has
moved past it and 7.29.1 was published on 2026-09-04, well beyond the 24
hour hold.
@shabaraba shabaraba changed the title chore(deps): update dependency fast-uri to >=4.1.4 <5 [security] fix(deps): bump fast-uri, undici and brace-expansion past their advisories Sep 30, 2026
@shabaraba
shabaraba marked this pull request as ready for review October 1, 2026 00:53
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:53
@shabaraba
shabaraba requested a review from a team as a code owner October 1, 2026 00:53
@shabaraba
shabaraba requested review from chihiro-adachi and nameless-mc and removed request for a team October 1, 2026 00:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The manifests and lockfile are consistent, and all targeted dependencies resolve to patched versions.

Review effort: Balanced
Findings: None

What changed in this PR

Updates vulnerable dependencies to patched releases across the workspace.

Changes:

  • Raises brace-expansion and fast-uri override floors.
  • Upgrades runtime dependency undici to 7.29.1.
  • Refreshes the lockfile and removes obsolete release-age exceptions.
File Description
package.json Updates security override ranges.
packages/​rest/​package.json Upgrades undici.
pnpm-lock.yaml Resolves patched dependency versions.
pnpm-workspace.yaml Removes obsolete release-age exclusions.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@shabaraba
shabaraba merged commit b949705 into main Oct 1, 2026
26 checks passed
@shabaraba
shabaraba deleted the fix/cve-2026-fast-uri branch October 1, 2026 02:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants