Skip to content

CVE-2026-75899 CVE-2026-75931 CVE-2026-75975 CVE-2026-76172 GHSA-qw65-cvwx-89v3 GHSA-58mr-gqgx-xq4g fast-uri: SSRF and host confusion (3.1.5 -> 3.1.7) - #1118

Open
vharseko wants to merge 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix/fast-uri-3.1.7
Open

Conversation

@vharseko

@vharseko vharseko commented Sep 3, 2026

Copy link
Copy Markdown
Member

Bumps fast-uri from 3.1.5 to 3.1.7 in both UI modules, combining two dependabot PRs into a single change.

Supersedes #1116 (/openam-ui/openam-ui-js-sdk) and #1117 (/openam-ui/openam-ui-ria).

Advisories fixed

Fixed in 3.1.7:

Fixed in 3.1.6:

Notes

fast-uri is a transitive dev dependency (via ajv, range ^3.0.1), so only the two package-lock.json files change; no package.json edits are required. The integrity hashes match the npm registry entry for 3.1.7.

…-cvwx-89v3 GHSA-58mr-gqgx-xq4g fast-uri: SSRF and host confusion (3.1.5 -> 3.1.7)

Combines dependabot PRs OpenIdentityPlatform#1116 (openam-ui-js-sdk) and OpenIdentityPlatform#1117 (openam-ui-ria)
into a single change.
@vharseko
vharseko requested a review from maximthomas September 3, 2026 07:50
@vharseko vharseko added security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF) dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code ui XUI / admin console / end-user UI labels Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF) ui XUI / admin console / end-user UI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants