[Aikido] Fix 20 security issues in fast-xml-parser, fast-uri, aws-cdk-lib and 5 more - #44
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
Conversation
Package lock diff2.4.1 -> 2.6.1 node_modules/@aws-cdk/asset-awscli-v1 2.2.242 -> 2.2.282 node_modules/@aws-cdk/asset-node-proxy-agent-v6 2.1.0 -> 2.1.2 node_modules/@aws-cdk/cloud-assembly-schema 45.2.0 -> 54.8.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/jsonschema 1.4.1 -> 1.5.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver 7.7.2 -> 7.8.4 node_modules/@aws-crypto/sha256-browser removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-utf8 removed node_modules/@aws-crypto/sha256-js removed node_modules/@aws-crypto/supports-web-crypto removed node_modules/@aws-crypto/util removed node_modules/@aws-crypto/util/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/util/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/util/node_modules/@smithy/util-utf8 removed node_modules/@aws-sdk/client-cognito-identity 3.840.0 -> 3.1080.0 node_modules/@aws-sdk/client-secrets-manager 3.840.0 -> 3.1080.0 node_modules/@aws-sdk/client-sso removed node_modules/@aws-sdk/core 3.840.0 -> 3.974.28 node_modules/@aws-sdk/credential-provider-cognito-identity 3.840.0 -> 3.972.53 node_modules/@aws-sdk/credential-provider-env 3.840.0 -> 3.972.54 node_modules/@aws-sdk/credential-provider-http 3.840.0 -> 3.972.56 node_modules/@aws-sdk/credential-provider-ini 3.840.0 -> 3.972.61 node_modules/@aws-sdk/credential-provider-node 3.840.0 -> 3.972.63 node_modules/@aws-sdk/credential-provider-process 3.840.0 -> 3.972.54 node_modules/@aws-sdk/credential-provider-sso 3.840.0 -> 3.972.60 node_modules/@aws-sdk/credential-provider-web-identity 3.840.0 -> 3.972.60 node_modules/@aws-sdk/credential-providers 3.840.0 -> 3.1080.0 node_modules/@aws-sdk/middleware-host-header removed node_modules/@aws-sdk/middleware-logger removed node_modules/@aws-sdk/middleware-recursion-detection removed node_modules/@aws-sdk/middleware-user-agent removed node_modules/@aws-sdk/nested-clients 3.840.0 -> 3.997.28 node_modules/@aws-sdk/region-config-resolver removed node_modules/@aws-sdk/token-providers 3.840.0 -> 3.1080.0 node_modules/@aws-sdk/types 3.840.0 -> 3.973.15 node_modules/@aws-sdk/util-endpoints removed node_modules/@aws-sdk/util-locate-window removed node_modules/@aws-sdk/util-user-agent-browser removed node_modules/@aws-sdk/util-user-agent-node removed node_modules/@aws-sdk/xml-builder 3.821.0 -> 3.972.33 node_modules/@smithy/abort-controller removed node_modules/@smithy/config-resolver removed node_modules/@smithy/core 3.6.0 -> 3.29.1 node_modules/@smithy/credential-provider-imds 4.0.6 -> 4.4.6 node_modules/@smithy/fetch-http-handler 5.0.4 -> 5.6.3 node_modules/@smithy/hash-node removed node_modules/@smithy/invalid-dependency removed node_modules/@smithy/is-array-buffer removed node_modules/@smithy/middleware-content-length removed node_modules/@smithy/middleware-endpoint removed node_modules/@smithy/middleware-retry removed node_modules/@smithy/middleware-serde removed node_modules/@smithy/middleware-stack removed node_modules/@smithy/node-config-provider removed node_modules/@smithy/node-http-handler 4.0.6 -> 4.9.3 node_modules/@smithy/property-provider removed node_modules/@smithy/protocol-http removed node_modules/@smithy/querystring-builder removed node_modules/@smithy/querystring-parser removed node_modules/@smithy/service-error-classification removed node_modules/@smithy/shared-ini-file-loader removed node_modules/@smithy/signature-v4 5.1.2 -> 5.6.2 node_modules/@smithy/smithy-client removed node_modules/@smithy/types 4.3.1 -> 4.15.1 node_modules/@smithy/url-parser removed node_modules/@smithy/util-base64 removed node_modules/@smithy/util-body-length-browser removed node_modules/@smithy/util-body-length-node removed node_modules/@smithy/util-buffer-from removed node_modules/@smithy/util-config-provider removed node_modules/@smithy/util-defaults-mode-browser removed node_modules/@smithy/util-defaults-mode-node removed node_modules/@smithy/util-endpoints removed node_modules/@smithy/util-hex-encoding removed node_modules/@smithy/util-middleware removed node_modules/@smithy/util-retry removed node_modules/@smithy/util-stream removed node_modules/@smithy/util-uri-escape removed node_modules/@smithy/util-utf8 removed node_modules/@types/uuid removed node_modules/ajv 6.12.6 -> 6.15.0 node_modules/aws-cdk-lib 2.204.0 -> 2.261.0 node_modules/aws-cdk-lib/node_modules/ajv removed node_modules/aws-cdk-lib/node_modules/ansi-regex removed node_modules/aws-cdk-lib/node_modules/ansi-styles removed node_modules/aws-cdk-lib/node_modules/astral-regex removed node_modules/aws-cdk-lib/node_modules/balanced-match 1.0.2 -> 4.0.4 node_modules/aws-cdk-lib/node_modules/brace-expansion 1.1.12 -> 5.0.6 node_modules/aws-cdk-lib/node_modules/color-convert removed node_modules/aws-cdk-lib/node_modules/color-name removed node_modules/aws-cdk-lib/node_modules/concat-map removed node_modules/aws-cdk-lib/node_modules/emoji-regex removed node_modules/aws-cdk-lib/node_modules/fast-deep-equal removed node_modules/aws-cdk-lib/node_modules/fast-uri removed node_modules/aws-cdk-lib/node_modules/fs-extra 11.3.0 -> 11.3.5 node_modules/aws-cdk-lib/node_modules/is-fullwidth-code-point removed node_modules/aws-cdk-lib/node_modules/json-schema-traverse removed node_modules/aws-cdk-lib/node_modules/jsonfile 6.1.0 -> 6.2.1 node_modules/aws-cdk-lib/node_modules/lodash.truncate removed node_modules/aws-cdk-lib/node_modules/minimatch 3.1.2 -> 10.2.5 node_modules/aws-cdk-lib/node_modules/require-from-string removed node_modules/aws-cdk-lib/node_modules/semver 7.7.2 -> 7.8.1 node_modules/aws-cdk-lib/node_modules/slice-ansi removed node_modules/aws-cdk-lib/node_modules/string-width removed node_modules/aws-cdk-lib/node_modules/strip-ansi removed node_modules/aws-cdk-lib/node_modules/table removed node_modules/aws-cdk-lib/node_modules/yaml 1.10.2 -> 1.10.3 node_modules/bowser 2.11.0 -> 2.14.1 node_modules/brace-expansion 1.1.12 -> 1.1.15 node_modules/constructs 10.4.2 -> 10.6.0 node_modules/fast-xml-parser removed node_modules/filelist/node_modules/brace-expansion 2.0.2 -> 2.1.1 node_modules/filelist/node_modules/minimatch 5.1.6 -> 5.1.9 node_modules/minimatch 3.1.2 -> 3.1.5 node_modules/strnum removed node_modules/uuid removed node_modules/@aws-sdk/credential-provider-login added node_modules/@aws-sdk/signature-v4-multi-region added node_modules/@aws/lambda-invoke-store added node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api added |
Author
|
Closed by Aikido: a new AutoFix has been created → #45 |
aikido-autofix
Bot
deleted the
fix/aikido-security-update-packages-63011094-gu8c
branch
July 9, 2026 23:43
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade dependencies to fix critical XML entity injection XSS, XML entity expansion DoS attacks, stack overflow in XML builder, URI normalization bypass, and other security vulnerabilities.
✅ No breaking changes for: fast-xml-parser, fast-uri, yaml, @smithy/config-resolver
✅ 20 CVEs resolved by this upgrade, including 1 critical 🚨 CVE
This PR will resolve the following CVEs:
preserveOrder:truecauses stack overflow leading to denial of service when processing certain inputs. The application crashes due to improper recursion handling during XML construction.*()and+()) generate regexps with catastrophic backtracking, causing severe ReDoS denial-of-service attacks with minimal input patterns triggering multi-second hangs.🤖 Remediation details
Fix security vulnerabilities in fast-xml-parser, fast-uri, aws-cdk-lib, brace-expansion, yaml, minimatch, @smithy/config-resolver, and ajv
Short summary
This PR remediates security vulnerabilities in eight npm packages: fast-xml-parser, fast-uri, aws-cdk-lib, brace-expansion, yaml, minimatch, @smithy/config-resolver, and ajv. The fixes are applied via three direct dependency spec bumps in the root
package.json(aws-cdk-lib,@aws-sdk/client-secrets-manager,@aws-sdk/credential-providers) and a lockfile-only transitive refresh (npm update ajv minimatch brace-expansion --package-lock-only), with all resolved versions recorded inpackage-lock.json.fast-xml-parser
fast-xml-parseris a transitive dependency pulled in by@aws-sdk/core, which is itself a transitive dependency of@aws-sdk/client-secrets-managerand@aws-sdk/credential-providers. The declared specs for both AWS SDK packages inpackage.jsonwere raised from^3.348.0to^3.844.0, which caused npm to resolve@aws-sdk/coreto3.974.28—a version that depends on a patchedfast-xml-parserrelease (≥ 4.5.5). No separatefast-xml-parserinstance remains in the lockfile after this parent bump.fast-uri
fast-uriis a transitive dependency ofajv(v8), which is itself nested insideaws-cdk-lib. Bumpingaws-cdk-libfrom^2.78.0to^2.260.0inpackage.jsonresolved the package to2.261.0, which carries anajvversion whose declared range (^3.0.1) allowsfast-uri≥ 3.1.3. After the lockfile refresh, no separatefast-uriinstance remains, indicating it was resolved to a patched version within the updatedaws-cdk-libsubtree.aws-cdk-lib
aws-cdk-libis a direct dependency declared inpackage.json. Its spec was raised from^2.78.0to^2.260.0, resolving to2.261.0in the lockfile, which satisfies the patched version floor of2.260.0. This bump was also the necessary parent change to pull in patched transitive versions ofyaml,minimatch,fast-uri, andajv(v8) nested withinaws-cdk-lib.yaml
yamlis a transitive dependency pinned exactly byaws-cdk-lib. The installed version1.10.2was below the patched floor of1.10.3. Bumpingaws-cdk-libto^2.260.0(resolved2.261.0) was sufficient:aws-cdk-lib@2.261.0pinsyamlat exactly1.10.3, which is the minimum patched version.minimatch
minimatchappears in three locations in the lockfile. The instance nested underaws-cdk-libmoved from3.1.2to10.2.5as a result of theaws-cdk-libparent bump. The root-level instance (shared by eslint, glob, jake, and others) and thefilelist-nested instance were updated from3.1.2and5.1.6to3.1.5and5.1.9respectively vianpm update minimatch --package-lock-only. All resolved versions satisfy the patched floor of3.1.4.brace-expansion
brace-expansionis a transitive dependency ofminimatchacross all three minimatch instances. After the minimatch updates, all three parentminimatchversions declare ranges that allow the patchedbrace-expansionversions (^1.1.7,^2.0.1,^5.0.5). Runningnpm update brace-expansion --package-lock-onlyresolved the instances to1.1.15,2.1.1, and5.0.6—the highest versions available through safe-chain at the time of the fix. These versions satisfy the lower-severity CVE patched floors (1.1.13/2.0.3for CVE-2026-33750;1.1.14/2.1.0for AIKIDO-2026-10477); the AIKIDO-2026-237551 floors (1.1.16,2.1.2,5.0.7) were suppressed by safe-chain's minimum package age requirement.@smithy/config-resolver
@smithy/config-resolveris a transitive dependency of@aws-sdk/client-secrets-manager,@aws-sdk/credential-providers, and related AWS SDK packages. Raising both AWS SDK direct deps to^3.844.0inpackage.jsonresolved them to3.1080.0, which carries@smithy/config-resolverat a version satisfying ≥ 4.4.0. No separate@smithy/config-resolverinstance remains in the lockfile after this parent bump.ajv
ajvappears in two major-version lines. The v6 instance (undereslintand@eslint/eslintrc) was updated from6.12.6to6.15.0vianpm update ajv --package-lock-only;eslint@8.57.1declares^6.12.4, which allows the patched6.14.0floor. The v8 instance nested insideaws-cdk-lib(undertable) was resolved to a patched version as a side-effect of theaws-cdk-libparent bump to2.261.0, and no separate v8 instance remains in the lockfile.Version changes
aws-cdk-lib^2.78.0(resolved2.204.0)^2.260.0(resolved2.261.0)@aws-sdk/client-secrets-manager^3.348.0(resolved3.840.0)^3.844.0(resolved3.1080.0)@aws-sdk/credential-providers^3.348.0(resolved3.840.0)^3.844.0(resolved3.1080.0)yaml1.10.21.10.3minimatch(aws-cdk-lib nested)3.1.210.2.5minimatch(root)3.1.23.1.5minimatch(filelist nested)5.1.65.1.9brace-expansion(root, under minimatch 3.x)1.1.121.1.15brace-expansion(aws-cdk-lib nested, under minimatch 10.x)1.1.125.0.6brace-expansion(filelist nested, under minimatch 5.x)2.0.22.1.1ajv(root, v6)6.12.66.15.0@aws-sdk/core3.840.03.974.28