Skip to content

CVE-2026-4926: Remediate CVE-2026-4926 in ccd-case-activity-api#576

Open
danlysiak wants to merge 1 commit into
masterfrom
cve-2026-4926-506f728f-ecfb-4c1f-b66d-f683f2499fcb
Open

CVE-2026-4926: Remediate CVE-2026-4926 in ccd-case-activity-api#576
danlysiak wants to merge 1 commit into
masterfrom
cve-2026-4926-506f728f-ecfb-4c1f-b66d-f683f2499fcb

Conversation

@danlysiak
Copy link
Copy Markdown
Member

Summary:
Updated the transitive path-to-regexp resolution from vulnerable 8.2.0 to 8.4.2 in both Yarn and npm lockfiles, and refreshed yarn-audit-known-issues to remove the path-to-regexp advisories for CVE-2026-4926. Verified yarn why path-to-regexp shows router@2.2.0 using path-to-regexp@8.4.2. yarn npm audit still exits non-zero for unrelated existing issues, but the target CVE/advisory is absent. yarn lint passed under Node 20 with one existing no-console warning, and yarn test:coverage passed under Node v20.19.4. test:end2end was skipped because Redis is not available on 127.0.0.1:6379.

Plan ID: 506f728f-ecfb-4c1f-b66d-f683f2499fcb

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant