Skip to content

UID2-7307 UID2-7308: fix form-data and ws CVEs (HIGH) across sub-packages#195

Merged
sophia-chen-ttd merged 2 commits into
mainfrom
syw-UID2-7307-fix-npm-vulns
Jun 16, 2026
Merged

UID2-7307 UID2-7308: fix form-data and ws CVEs (HIGH) across sub-packages#195
sophia-chen-ttd merged 2 commits into
mainfrom
syw-UID2-7307-fix-npm-vulns

Conversation

@sophia-chen-ttd

Copy link
Copy Markdown
Contributor

Summary

Fixes two HIGH severity vulnerabilities across all affected sub-packages:

  • CVE-2026-12143 — form-data multipart library vulnerability. Adds form-data>=4.0.6 npm override to 7 affected sub-packages; all lock files resolve to 4.0.6.

  • CVE-2026-48779 — ws WebSocket memory exhaustion DoS. Adds ws>=7.5.11 npm override to 2 react-client-side sub-packages; lock files resolve to 8.21.0.

  • Jira: UID2-7307, UID2-7308

Affected sub-packages

  • web-integrations/google-secure-signals/client-server — form-data
  • web-integrations/google-secure-signals/server-side — form-data
  • web-integrations/google-secure-signals/react-client-side — form-data, ws
  • web-integrations/javascript-sdk/client-server — form-data
  • web-integrations/javascript-sdk/react-client-side — form-data, ws
  • web-integrations/prebid-integrations/client-server — form-data
  • web-integrations/server-side — form-data

Test plan

…6-48779 (UID2-7307, UID2-7308)

CVE-2026-12143 (HIGH): form-data multipart library vulnerability.
Adds npm override form-data>=4.0.6 to each affected sub-package so
all lock files resolve to the patched 4.0.6 release.

CVE-2026-48779 (HIGH): ws WebSocket memory exhaustion DoS.
Adds npm override ws>=7.5.11 to react-client-side sub-packages so
all lock files resolve to 8.21.0.
CVE-2026-1615 (jsonpath Arbitrary Code Execution) was missing a Trivy
exp: field despite having a comment expiry of 2026-03-19. Fix confirmed
pending in upstream (latest: 1.3.0); setting exp:2026-09-16 to track.
@sophia-chen-ttd sophia-chen-ttd merged commit e8d57bd into main Jun 16, 2026
2 checks passed
@sophia-chen-ttd sophia-chen-ttd deleted the syw-UID2-7307-fix-npm-vulns branch June 16, 2026 05:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants