Skip to content

Commit 71e4249

Browse files
massongitclaude
andauthored
Fix undici security vulnerability (CVE-2026-22036) (#1578)
Override undici version to 6.23.0 to address CVE-2026-22036, which affects versions below 6.23.0. This fixes an unbounded decompression chain vulnerability in HTTP responses. Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
1 parent ce69680 commit 71e4249

2 files changed

Lines changed: 7 additions & 16 deletions

File tree

package-lock.json

Lines changed: 4 additions & 16 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,9 @@
3434
"engines": {
3535
"node": "24.13.0"
3636
},
37+
"overrides": {
38+
"undici": "^6.23.0"
39+
},
3740
"standard": {
3841
"ignore": [
3942
"dist/"

0 commit comments

Comments
 (0)