Skip to content

Commit afb87a5

Browse files
Sync Collecting Fix Commits: Sun Sep 13 08:35:18 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent a87e214 commit afb87a5

3 files changed

Lines changed: 102 additions & 7 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 98 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,104 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-36QH-HPMX-M9CV": {
5+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
6+
},
7+
"GHSA-6JFR-PC8J-PP9Q": {
8+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
9+
},
10+
"GHSA-7CC7-PPV7-MJWP": {
11+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
12+
},
13+
"GHSA-9F9V-4H96-WH6M": {
14+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
15+
},
16+
"GHSA-C37V-9FMR-FHCJ": {
17+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
18+
},
19+
"GHSA-CMHF-4MFX-3GF7": {
20+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
21+
},
22+
"GHSA-FVCQ-6V6M-MMRF": {
23+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
24+
},
25+
"GHSA-H8FJ-8C8P-PCWW": {
26+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
27+
},
28+
"GHSA-W259-7X22-FR4J": {
29+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
30+
},
31+
"GHSA-W78C-FX7Q-9X8M": {
32+
"d9d5fbda5e2afa6df16ceeaa3ce976fe7bdadcb6": "Publish Advisories\n\nGHSA-36qh-hpmx-m9cv\nGHSA-6jfr-pc8j-pp9q\nGHSA-7cc7-ppv7-mjwp\nGHSA-9f9v-4h96-wh6m\nGHSA-c37v-9fmr-fhcj\nGHSA-cmhf-4mfx-3gf7\nGHSA-fvcq-6v6m-mmrf\nGHSA-h8fj-8c8p-pcww\nGHSA-w259-7x22-fr4j\nGHSA-w78c-fx7q-9x8m"
33+
},
34+
"GHSA-23FC-J83W-RXQ7": {
35+
"00e9b63d1918e17bc10b1585d7c3e63606243662": "Publish Advisories\n\nGHSA-23fc-j83w-rxq7\nGHSA-2mvj-cvq7-662g\nGHSA-5cjj-j77f-rq2g\nGHSA-8vpg-vfm4-mhh5\nGHSA-wr2r-r9vc-rr7g"
36+
},
37+
"GHSA-2MVJ-CVQ7-662G": {
38+
"00e9b63d1918e17bc10b1585d7c3e63606243662": "Publish Advisories\n\nGHSA-23fc-j83w-rxq7\nGHSA-2mvj-cvq7-662g\nGHSA-5cjj-j77f-rq2g\nGHSA-8vpg-vfm4-mhh5\nGHSA-wr2r-r9vc-rr7g"
39+
},
40+
"GHSA-5CJJ-J77F-RQ2G": {
41+
"00e9b63d1918e17bc10b1585d7c3e63606243662": "Publish Advisories\n\nGHSA-23fc-j83w-rxq7\nGHSA-2mvj-cvq7-662g\nGHSA-5cjj-j77f-rq2g\nGHSA-8vpg-vfm4-mhh5\nGHSA-wr2r-r9vc-rr7g"
42+
},
43+
"GHSA-8VPG-VFM4-MHH5": {
44+
"00e9b63d1918e17bc10b1585d7c3e63606243662": "Publish Advisories\n\nGHSA-23fc-j83w-rxq7\nGHSA-2mvj-cvq7-662g\nGHSA-5cjj-j77f-rq2g\nGHSA-8vpg-vfm4-mhh5\nGHSA-wr2r-r9vc-rr7g"
45+
},
46+
"GHSA-WR2R-R9VC-RR7G": {
47+
"00e9b63d1918e17bc10b1585d7c3e63606243662": "Publish Advisories\n\nGHSA-23fc-j83w-rxq7\nGHSA-2mvj-cvq7-662g\nGHSA-5cjj-j77f-rq2g\nGHSA-8vpg-vfm4-mhh5\nGHSA-wr2r-r9vc-rr7g"
48+
},
49+
"GHSA-79QW-G39G-MFXC": {
50+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
51+
},
52+
"GHSA-92FW-P64J-PHVM": {
53+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
54+
},
55+
"GHSA-FF59-MHRH-HCVF": {
56+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
57+
},
58+
"GHSA-FJ9C-WR2V-556H": {
59+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
60+
},
61+
"GHSA-H6W4-32PJ-Q5P4": {
62+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
63+
},
64+
"GHSA-QCWQ-WQP5-V342": {
65+
"3a27bb4e050ea7edab395137a4fd352aa023c662": "Publish Advisories\n\nGHSA-79qw-g39g-mfxc\nGHSA-92fw-p64j-phvm\nGHSA-ff59-mhrh-hcvf\nGHSA-fj9c-wr2v-556h\nGHSA-h6w4-32pj-q5p4\nGHSA-qcwq-wqp5-v342"
66+
},
67+
"GHSA-XM8C-HVJF-C5Q9": {
68+
"84fc111de91493a574245991f953f7aaae5c3812": "Improve GHSA-xm8c-hvjf-c5q9",
69+
"3ea09c7ae85101f1a6f28db22731d5444e18b17e": "Improve GHSA-xm8c-hvjf-c5q9"
70+
},
71+
"GHSA-325J-MG25-8Q58": {
72+
"c9d0a53a9eccb97872a5cc03be1de500c5e2368b": "Improve GHSA-325j-mg25-8q58",
73+
"7cb1175d90c1048d961a05685204716aceafbe5b": "Publish Advisories\n\nGHSA-8vm2-c32j-mvfr\nGHSA-r2g5-993q-664g\nGHSA-325j-mg25-8q58"
74+
},
75+
"GHSA-3GR6-JFW8-H5JH": {
76+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
77+
},
78+
"GHSA-7GR9-32JG-84C9": {
79+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
80+
},
81+
"GHSA-7JJW-49WP-PR5H": {
82+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
83+
},
84+
"GHSA-8VVF-7V96-575P": {
85+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
86+
},
87+
"GHSA-GCC5-22R7-2JF2": {
88+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
89+
},
90+
"GHSA-HRG9-RFPJ-46W2": {
91+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
92+
},
93+
"GHSA-JRP2-P3PX-F5P5": {
94+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
95+
},
96+
"GHSA-W26J-6RP4-VHJ5": {
97+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
98+
},
99+
"GHSA-X282-35XQ-G9Q7": {
100+
"5d7c2e5f9ab6cf4681e1275fb9240eb0c6197ab4": "Publish Advisories\n\nGHSA-3gr6-jfw8-h5jh\nGHSA-7gr9-32jg-84c9\nGHSA-7jjw-49wp-pr5h\nGHSA-8vvf-7v96-575p\nGHSA-gcc5-22r7-2jf2\nGHSA-hrg9-rfpj-46w2\nGHSA-jrp2-p3px-f5p5\nGHSA-w26j-6rp4-vhj5\nGHSA-x282-35xq-g9q7"
101+
},
4102
"GHSA-VHX5-8PFJ-7WRV": {
5103
"b628004db5d2ae75fce69e56251dc203c70f25a2": "Publish GHSA-vhx5-8pfj-7wrv"
6104
},
@@ -273,9 +371,6 @@
273371
"9c9b778117b293269aeeeb93c71fcc212c5b4aa3": "Publish Advisories\n\nGHSA-2jgc-c4h3-xw55\nGHSA-39g5-2q66-34fm\nGHSA-9qf7-q6gx-q652\nGHSA-v69h-c25q-f3jf\nGHSA-3hc6-3p33-wq57\nGHSA-456x-9xrh-6x87\nGHSA-462c-92rv-647m\nGHSA-7grq-qcph-gj3c\nGHSA-8vm2-c32j-mvfr\nGHSA-95pw-q9xh-p66r\nGHSA-chxj-gxww-q98w\nGHSA-g5q2-6jvc-qfhh\nGHSA-mf7v-x7r6-fq57\nGHSA-pqrj-4gwg-h5f7\nGHSA-qvj8-gwpm-4x49\nGHSA-r2g5-993q-664g\nGHSA-v73p-f52r-fmmr\nGHSA-x6g3-x68w-mv5x",
274372
"756b0dd5387c81b52471d32952666f23933ff1cc": "Publish Advisories\n\nGHSA-9qf7-q6gx-q652\nGHSA-469x-qwp6-693q\nGHSA-4c54-mjrj-jwj4\nGHSA-4ph5-83mw-vm42\nGHSA-4r2h-m6wp-gxg9\nGHSA-5p7p-jgvj-4v95\nGHSA-6xrf-25hf-gfpv\nGHSA-74fp-pmv2-rh3f\nGHSA-7gx3-r5q9-6j33\nGHSA-7j37-rf7v-jf5c\nGHSA-7m4f-cfr6-pwp7\nGHSA-7rjc-r662-4qm8\nGHSA-7ww4-jpp4-x9fw\nGHSA-8vm2-c32j-mvfr\nGHSA-c83q-p66f-qr9p\nGHSA-chxj-gxww-q98w\nGHSA-g944-p6hc-2mch\nGHSA-gxfr-4w92-cm52\nGHSA-hq2m-9p82-5366\nGHSA-jx39-26rr-cwqp\nGHSA-pqrj-4gwg-h5f7\nGHSA-qvj8-gwpm-4x49\nGHSA-r2g5-993q-664g\nGHSA-v73p-f52r-fmmr"
275373
},
276-
"GHSA-325J-MG25-8Q58": {
277-
"7cb1175d90c1048d961a05685204716aceafbe5b": "Publish Advisories\n\nGHSA-8vm2-c32j-mvfr\nGHSA-r2g5-993q-664g\nGHSA-325j-mg25-8q58"
278-
},
279374
"GHSA-PQRJ-4GWG-H5F7": {
280375
"1047221dfcd5dfdb30acfa1ee3763439673064a5": "Publish Advisories\n\nGHSA-pqrj-4gwg-h5f7\nGHSA-qvj8-gwpm-4x49\nGHSA-v73p-f52r-fmmr",
281376
"9c9b778117b293269aeeeb93c71fcc212c5b4aa3": "Publish Advisories\n\nGHSA-2jgc-c4h3-xw55\nGHSA-39g5-2q66-34fm\nGHSA-9qf7-q6gx-q652\nGHSA-v69h-c25q-f3jf\nGHSA-3hc6-3p33-wq57\nGHSA-456x-9xrh-6x87\nGHSA-462c-92rv-647m\nGHSA-7grq-qcph-gj3c\nGHSA-8vm2-c32j-mvfr\nGHSA-95pw-q9xh-p66r\nGHSA-chxj-gxww-q98w\nGHSA-g5q2-6jvc-qfhh\nGHSA-mf7v-x7r6-fq57\nGHSA-pqrj-4gwg-h5f7\nGHSA-qvj8-gwpm-4x49\nGHSA-r2g5-993q-664g\nGHSA-v73p-f52r-fmmr\nGHSA-x6g3-x68w-mv5x",
@@ -5430,9 +5525,6 @@
54305525
"GHSA-FWJF-M4QW-9F2X": {
54315526
"094a1606bc92ac7d9b9d5fba225b211ec3a52839": "Publish Advisories\n\nGHSA-8jj7-4v57-frf5\nGHSA-fwjf-m4qw-9f2x"
54325527
},
5433-
"GHSA-XM8C-HVJF-C5Q9": {
5434-
"3ea09c7ae85101f1a6f28db22731d5444e18b17e": "Improve GHSA-xm8c-hvjf-c5q9"
5435-
},
54365528
"GHSA-36P7-VC44-83PF": {
54375529
"da42caf96d5b00a143024218edfbeb86d751568e": "Publish GHSA-36p7-vc44-83pf"
54385530
},

data/fix-commits/bun-1f8d61fe.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
{
22
"vcs_url": "https://github.com/oven-sh/bun",
33
"vulnerabilities": {
4+
"CVE-2026-58044": {
5+
"99eadd33e6d206130e1aae2de842d061c9dbf351": "node:http: reject requests with more header fields than server.maxHeadersCount\n\nA lowered server.maxHeadersCount cut the header list the handler saw, after\nthe parser had framed the message with every field. A Content-Length past\nthe limit was hidden from req.headers and req.rawHeaders and still\ndelimited a body. Node rejects such a request since nodejs/node 821688aaa0\n(CVE-2026-58044).\n\nThe native server now takes the limit as the bound of the field loop in\nuWS getHeaders, so the existing parse error path answers: 'clientError'\nwith HPE_HEADER_OVERFLOW, 431 by default, no more parsing on the\nconnection. Trailer fields count from zero against the same limit. The\nvalue reaches the parser at listen() and on every later assignment.\n\nThe llhttp binding gets Node's TrackHeaderPair for request parsers, in the\nrevision that reads maxHeaderPairs once per header section\n(nodejs/node#64988). Responses keep truncating. This covers sockets passed\nto server.emit('connection') and the HTTP/1.1 connections of an allowHTTP1\nHTTP/2 server. That listener now also starts from Node's 2000-pair default\nand assembles the header blocks and trailers the parser flushes through\nkOnHeaders. Before, a request with 32 or more fields reached the handler\nwith only its last block, so Host and Content-Length were hidden there too.\n\nThe JS truncation of rawHeaders and rawTrailers is gone. The vendored Node\ntests follow upstream: two added, two updated, and\ntest-http-rawheaders-limit.js removed."
6+
},
47
"CVE-2026-56850": {
58
"6b19264837f813157eee6a03ba8c2a8e72945206": "node:https: key the Agent pool name by what object-valued and file TLS options hold\n\nhttps.Agent#getName() appended ca, cert, key, pfx, crl and dhparam with\nstring coercion. A { buf | pem, passphrase } entry, an ArrayBuffer and a\nBlob all coerce to \"[object ...]\", and the Bun-only certFile, keyFile and\ncaFile options were not in the name. Requests that present different client\ncertificates then shared one pool name, one keep-alive connection and one\ncached TLS session.\n\npoolKeyPart() keeps Node's name for strings, Buffers, TypedArrays and\narrays of those. It keys a pfx entry the way Node's getPfxAgentKey() does\n(nodejs/node 9f03017f38, CVE-2026-56850), keys a key entry by its pem, keys\nan ArrayBuffer by its bytes, and keys every other object by identity.\ncertFile, keyFile and caFile are labelled parts at the end of the name."
69
},

data/fix-commits/ray-0ccf055f.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"vcs_url": "https://github.com/ray-project/ray",
33
"vulnerabilities": {
44
"CVE-2026-54399": {
5-
"e26e0f279506788d3afc65f55266068c865614dc": "[Java] Update httpcore5 to 5.4.3 (#66081)\n\n## Description\n\nUpdates the bundled Maven dependency\n`org.apache.httpcomponents.core5:httpcore5` from 5.0.2 to 5.4.3 to\naddress CVE-2026-54399.\n\nAdds a regression test that checks the pinned version so the patched\ndependency is not accidentally downgraded.\n\nDuplicate check: searched open PRs for `66013` and `httpcore5 5.4.3`; no\nrelated PRs were found.\n\n## Related issues\n\nFixes #66013\n\n## Testing\n\n- `.venv/bin/python -m pytest -q\nci/build/bundled_dependency_versions_test.py` \u2014 3 passed\n- `.venv/bin/pre-commit run --files java/dependencies.bzl\nci/build/bundled_dependency_versions_test.py` \u2014 passed\n- `npx --yes @bazel/bazelisk@latest build\n@maven//:org_apache_httpcomponents_core5_httpcore5` \u2014 passed and\nresolved httpcore5 5.4.3\n- `npx --yes @bazel/bazelisk@latest build --jobs=4\n//java:io_ray_ray_serve` \u2014 passed\n\n## Additional information\n\nAI assistance was used to implement and validate this change. The\nsubmitter reviewed and understands the submitted changes.\n\nSigned-off-by: Rajat Jaiswal <16982843+onlinerj@users.noreply.github.com>\n(cherry picked from commit db9546de2459e635d252b71a95d0c2629bd4f578)\nSigned-off-by: elliot-barn <elliot.barnwell@anyscale.com>",
5+
"e15d2899ee923e304dd76e175bceb9e862f2ff49": "[cherry-pick][2.59.0][Java] Update httpcore5 to 5.4.3 (#66081) (#66130)\n\nCherry-pick of #66081 (db9546de24) onto `releases/2.59.0`. Applied\ncleanly with `git cherry-pick -x`.\n\n## Why this belongs in 2.59.0\n\nBumps the bundled Maven dependency\n`org.apache.httpcomponents.core5:httpcore5` from 5.0.2 to 5.4.3 for\nCVE-2026-54399 (#66013). This is not a test-only dependency:\n`io_ray_ray_serve` declares `httpcore5` in its production `deps`\n(`java/BUILD.bazel:203`), the `ray_dist` fat jar bundles\n`api`/`runtime`/`serve` with their runtime deps, and that shaded jar\nships as `ray/jars/ray_dist.jar` inside the Linux wheels (built via\n`bazel run //java:gen_ray_java_pkg` in\n`ci/build/build-manylinux-ray.sh`; included by `python/setup.py` when\npresent) and as a compile-scope dependency in the published\n`io.ray:ray-serve` POM. Without this pick, 2.59.0 wheels carry the\nvulnerable 5.0.2.\n\nRisk: a one-line Maven version bump plus the version-guard test from the\noriginal PR. `httpclient5` stays at 5.0.3 (built against httpcore5\n5.0.2); HttpCore is API-compatible within 5.x and the original PR's CI\n(all checks green) exercised the serve Java tests that use\n`httpclient5-fluent`. No Python dependency or lock changes.\n\n## Testing\n\n- `python -m pytest -q ci/build/bundled_dependency_versions_test.py` on\nthis branch \u2192 3 passed (includes the new\n`test_ray_dist_jar_uses_patched_httpcore5_version`)\n- `pre-commit run --files java/dependencies.bzl\nci/build/bundled_dependency_versions_test.py` \u2192 clean\n- Original PR #66081: 6/6 checks passed on master before merge\n\nOriginal PR: #66081. Fixes #66013 on the release line.\n\n\ud83e\udd16 Generated with [Claude Code](https://claude.com/claude-code)\n\nSigned-off-by: Rajat Jaiswal <16982843+onlinerj@users.noreply.github.com>\nSigned-off-by: elliot-barn <elliot.barnwell@anyscale.com>\nCo-authored-by: Rajat Jaiswal <16982843+onlinerj@users.noreply.github.com>",
66
"db9546de2459e635d252b71a95d0c2629bd4f578": "[Java] Update httpcore5 to 5.4.3 (#66081)\n\n## Description\n\nUpdates the bundled Maven dependency\n`org.apache.httpcomponents.core5:httpcore5` from 5.0.2 to 5.4.3 to\naddress CVE-2026-54399.\n\nAdds a regression test that checks the pinned version so the patched\ndependency is not accidentally downgraded.\n\nDuplicate check: searched open PRs for `66013` and `httpcore5 5.4.3`; no\nrelated PRs were found.\n\n## Related issues\n\nFixes #66013\n\n## Testing\n\n- `.venv/bin/python -m pytest -q\nci/build/bundled_dependency_versions_test.py` \u2014 3 passed\n- `.venv/bin/pre-commit run --files java/dependencies.bzl\nci/build/bundled_dependency_versions_test.py` \u2014 passed\n- `npx --yes @bazel/bazelisk@latest build\n@maven//:org_apache_httpcomponents_core5_httpcore5` \u2014 passed and\nresolved httpcore5 5.4.3\n- `npx --yes @bazel/bazelisk@latest build --jobs=4\n//java:io_ray_ray_serve` \u2014 passed\n\n## Additional information\n\nAI assistance was used to implement and validate this change. The\nsubmitter reviewed and understands the submitted changes.\n\nSigned-off-by: Rajat Jaiswal <16982843+onlinerj@users.noreply.github.com>"
77
},
88
"CVE-2026-7246": {

0 commit comments

Comments
 (0)