Skip to content

fix(deps): vuln minor upgrades — 13 packages (minor: 7 · patch: 6) [hugo/package.json] - #39580

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/hugo/0-1788169735
Open

fix(deps): vuln minor upgrades — 13 packages (minor: 7 · patch: 6) [hugo/package.json]#39580
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
masterfrom
engraver-auto-version-upgrade/minorpatch/npm/hugo/0-1788169735

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Critical-severity security update — 15 packages upgraded (MINOR changes included)

Manifests changed:

  • hugo/package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
@babel/traverse 7.12.5 7.29.8 minor Transitive 2 CRITICAL
lodash 4.17.21 4.18.1 minor Direct 4 HIGH, 4 MEDIUM
postcss 8.5.3 8.5.26 patch Transitive 4 HIGH, 4 MEDIUM
ws 7.4.0 7.5.13 minor Transitive 4 HIGH, 2 MEDIUM
@grpc/grpc-js 1.10.8 1.10.12 patch Transitive 4 HIGH, 2 MEDIUM
lodash.template 4.5.0 4.18.1 minor Transitive 4 HIGH
linkify-it 5.0.0 5.0.2 patch Transitive 4 HIGH
nanoid 3.3.8 3.3.18 patch Transitive 4 HIGH
js-yaml 4.1.0 4.3.2 minor Transitive 3 HIGH, 4 MEDIUM
js-yaml 3.14.1 3.15.2 minor Direct 3 HIGH, 4 MEDIUM
picomatch 2.2.2 2.3.2 minor Transitive 2 HIGH, 2 MEDIUM
qs 6.5.2 6.15.3 minor Transitive 2 HIGH, 2 MEDIUM
ws 8.18.1 8.21.3 minor Transitive 2 HIGH, 2 MEDIUM
glob-parent 5.1.1 5.1.2 patch Transitive 2 HIGH
http-cache-semantics 4.1.0 4.1.1 patch Transitive 2 HIGH

Security Details

🚨 Critical & High Severity (46 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
@babel/traverse CVE-2023-45133 CRITICAL Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code 7.12.5 - -
@babel/traverse GHSA-67hx-6x53-jw92 CRITICAL Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code 7.12.5 7.23.2 -
@grpc/grpc-js CVE-2026-48069 HIGH @grpc/grps-js: An incoming malformed compressed message can cause a client or server crash 1.10.8 - -
@grpc/grpc-js GHSA-5375-pq7m-f5r2 HIGH @grpc/grpc-js: A malformed request can cause a server crash 1.10.8 1.9.16 -
@grpc/grpc-js CVE-2026-48068 HIGH @grpc/grps-js: A malformed request can cause a server crash 1.10.8 - -
@grpc/grpc-js GHSA-99f4-grh7-6pcq HIGH @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash 1.10.8 1.9.16 -
glob-parent GHSA-ww39-953v-wcq6 HIGH glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex 5.1.1 5.1.2 -
glob-parent CVE-2020-28469 HIGH - 5.1.1 - -
http-cache-semantics GHSA-rc47-6667-2j5j HIGH http-cache-semantics vulnerable to Regular Expression Denial of Service 4.1.0 4.1.1 -
http-cache-semantics CVE-2022-25881 HIGH - 4.1.0 - -
js-yaml CVE-2026-59869 HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 4.1.0 - -
js-yaml GHSA-5p4m-2wfm-xmqj HIGH JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported 4.1.0 4.3.1 -
js-yaml GHSA-52cp-r559-cp3m HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 4.1.0 3.15.0 -
js-yaml GHSA-5p4m-2wfm-xmqj HIGH JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported 3.14.1 4.3.1 -
js-yaml CVE-2026-59869 HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 3.14.1 - -
js-yaml GHSA-52cp-r559-cp3m HIGH js-yaml: YAML merge-key chains can force quadratic CPU consumption 3.14.1 3.15.0 -
linkify-it GHSA-v245-v573-v5vm HIGH linkify-it: Quadratic-complexity DoS via the mailto: validator scan-loop on attacker text 5.0.0 5.0.2 -
linkify-it CVE-2026-59887 HIGH linkify-it: Quadratic-complexity DoS via the mailto: validator scan-loop on attacker text 5.0.0 - -
linkify-it GHSA-22p9-wv53-3rq4 HIGH LinkifyIt#match scan loop has quadratic algorithmic complexity 5.0.0 5.0.1 -
linkify-it CVE-2026-48801 HIGH linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop 5.0.0 - -
lodash CVE-2026-4800 HIGH lodash vulnerable to Code Injection via _.template imports key names 4.17.21 - -
lodash GHSA-35jh-r3h4-6jhm HIGH Command Injection in lodash 4.17.21 4.17.21 -
lodash CVE-2021-23337 HIGH - 4.17.21 - -
lodash GHSA-r5fr-rjxr-66jc HIGH lodash vulnerable to Code Injection via _.template imports key names 4.17.21 4.18.0 -
lodash.template GHSA-r5fr-rjxr-66jc HIGH lodash vulnerable to Code Injection via _.template imports key names 4.5.0 4.18.0 -
lodash.template CVE-2021-23337 HIGH - 4.5.0 - -
lodash.template CVE-2026-4800 HIGH lodash vulnerable to Code Injection via _.template imports key names 4.5.0 - -
lodash.template GHSA-35jh-r3h4-6jhm HIGH Command Injection in lodash 4.5.0 - -
nanoid GHSA-28wg-ghj8-5hjv HIGH nanoid: non-secure generators can loop indefinitely with negative size 3.3.8 3.3.16 -
nanoid GHSA-2v37-7h3g-55p8 HIGH nanoid: custom generators can loop indefinitely when size is zero 3.3.8 3.3.18 -
nanoid CVE-2026-67214 HIGH nanoid Infinite Loop via Negative Size in non-secure module 3.3.8 - -
nanoid CVE-2026-67213 HIGH nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom 3.3.8 - -
picomatch GHSA-c2c7-rcm5-vvqj HIGH Picomatch has a ReDoS vulnerability via extglob quantifiers 2.2.2 4.0.4 -
picomatch CVE-2026-33671 HIGH Picomatch has a ReDoS vulnerability via extglob quantifiers 2.2.2 - -
postcss GHSA-6g55-p6wh-862q HIGH PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments 8.5.3 8.5.12 -
postcss CVE-2026-45623 HIGH PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments 8.5.3 - -
postcss GHSA-r28c-9q8g-f849 HIGH PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure 8.5.3 8.5.18 -
postcss CVE-2026-73646 HIGH PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure 8.5.3 - -
qs GHSA-hrpp-h998-j3pp HIGH qs vulnerable to Prototype Pollution 6.5.2 6.10.3 -
qs CVE-2022-24999 HIGH - 6.5.2 - -
ws GHSA-96hv-2xvq-fx4p HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 7.4.0 5.2.5 -
ws CVE-2024-37890 HIGH Denial of service when handling a request with many HTTP headers in ws 7.4.0 - -
ws GHSA-96hv-2xvq-fx4p HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 8.18.1 5.2.5 -
ws CVE-2026-48779 HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 8.18.1 - -
ws GHSA-3h5v-q93c-6h6q HIGH ws affected by a DoS when handling a request with many HTTP headers 7.4.0 5.2.4 -
ws CVE-2026-48779 HIGH ws: Memory exhaustion DoS from tiny fragments and data chunks 7.4.0 - -
ℹ️ Other Vulnerabilities (26)
Package CVE Severity Summary Unsafe Version Fixed In Case
@grpc/grpc-js GHSA-7v5v-9h63-cj86 MODERATE @grpc/grpc-js can allocate memory for incoming messages well above configured limits 1.10.8 1.10.9 -
@grpc/grpc-js CVE-2024-37168 MODERATE @grpc/grpc-js can allocate memory for incoming messages well above configured limits 1.10.8 - -
js-yaml CVE-2026-53550 MODERATE js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases 4.1.0 - -
js-yaml GHSA-h67p-54hq-rp68 MODERATE JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases 3.14.1 4.2.0 -
js-yaml GHSA-mh29-5h37-fv8m MODERATE js-yaml has prototype pollution in merge (<<) 3.14.1 4.1.1 -
js-yaml CVE-2025-64718 MODERATE js-yaml has prototype pollution in merge (<<) 3.14.1 - -
js-yaml CVE-2025-64718 MODERATE js-yaml has prototype pollution in merge (<<) 4.1.0 - -
js-yaml GHSA-mh29-5h37-fv8m MODERATE js-yaml has prototype pollution in merge (<<) 4.1.0 4.1.1 -
js-yaml CVE-2026-53550 MODERATE js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases 3.14.1 - -
js-yaml GHSA-h67p-54hq-rp68 MODERATE JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases 4.1.0 4.2.0 -
lodash GHSA-xxjr-mmjv-4gpg MODERATE Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions 4.17.21 4.17.23 -
lodash CVE-2025-13465 MODERATE Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions 4.17.21 - -
lodash GHSA-f23m-r3pf-42rh MODERATE lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit 4.17.21 4.18.0 -
lodash CVE-2026-2950 MODERATE lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit 4.17.21 - -
picomatch CVE-2026-33672 MODERATE Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching 2.2.2 - -
picomatch GHSA-3v7f-55p6-f55p MODERATE Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching 2.2.2 4.0.4 -
postcss GHSA-fxqj-rqcc-2cmp MODERATE PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset 8.5.3 8.5.23 -
postcss CVE-2026-41305 MODERATE PostCSS has XSS via Unescaped </style> in its CSS Stringify Output 8.5.3 - -
postcss GHSA-qx2v-qp2m-jg93 MODERATE PostCSS has XSS via Unescaped </style> in its CSS Stringify Output 8.5.3 8.5.10 -
postcss CVE-2026-69153 MODERATE PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset 8.5.3 - -
qs GHSA-6rw7-vpxm-498p MODERATE qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion 6.5.2 6.14.1 -
qs CVE-2025-15284 MODERATE arrayLimit bypass in bracket notation allows DoS via memory exhaustion 6.5.2 - -
ws CVE-2026-45736 MODERATE ws: Uninitialized memory disclosure 8.18.1 - -
ws GHSA-58qx-3vcg-4xpx MODERATE ws: Uninitialized memory disclosure 8.18.1 8.20.1 -
ws CVE-2021-32640 MODERATE - 7.4.0 - -
ws GHSA-6fc8-4gx4-v693 MODERATE ReDoS in Sec-Websocket-Protocol header 7.4.0 7.4.6 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with master — rebased onto 482a596.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-03ec73
dd-octo-sts-03ec73 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/npm/hugo/0-1788169735 branch from 317ed4c to 1386be2 Compare September 4, 2026 10:16
@datadog-prod-us1-5

This comment has been minimized.

dd-octo-sts-2c363b Bot and others added 2 commits September 8, 2026 13:05
…ackage.json]

Co-authored-by: dd-octo-sts-03ec73[bot] <256648721+dd-octo-sts-03ec73[bot]@users.noreply.github.com>
Co-authored-by: dd-octo-sts-03ec73[bot] <256648721+dd-octo-sts-03ec73[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase complete

Branch is up to date with master — rebased onto fde6b8c.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-2c363b
dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/minorpatch/npm/hugo/0-1788169735 branch from 1386be2 to a34274c Compare September 8, 2026 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants