fix(ui): pin proxy-addr to 2.0.8 to patch the IP spoofing advisory (#12957)

This commit is contained in:
Alejandro Bailo
2026-10-06 10:10:17 +02:00
committed by GitHub
parent 0321a4f167
commit f850199645
3 changed files with 11 additions and 4 deletions
@@ -0,0 +1 @@
`proxy-addr` to 2.0.8, patching IP spoofing through IPv4-mapped IPv6 trust subnets (GHSA-jqcg-44mw-7w3h)
+5 -4
View File
@@ -44,6 +44,7 @@ overrides:
ip-address: 10.3.1
mermaid: 11.16.1
body-parser: 2.3.0
proxy-addr: 2.0.8
'@humanfs/node': 0.16.8
js-yaml: 4.3.1
@@ -6164,8 +6165,8 @@ packages:
property-information@7.1.0:
resolution: {integrity: sha512-TwEZ+X+yCJmYfL7TPUOcvBZ4QfoT5YenQiJuX//0th53DE6w0xxLEtfK3iyryQFddXuvkIk51EEgrJQ0WJkOmQ==}
proxy-addr@2.0.7:
resolution: {integrity: sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==}
proxy-addr@2.0.8:
resolution: {integrity: sha512-5nnx0yGyVUcY6t9RnWcARWtwT9F1D8O9rt08htPvnd49W1IgZtmLkhu9WfMzQj1cFxjHIO6connUNVW5k7AVyQ==}
engines: {node: '>= 0.10'}
proxy-from-env@1.1.0:
@@ -12002,7 +12003,7 @@ snapshots:
on-finished: 2.4.1
once: 1.4.0
parseurl: 1.3.3
proxy-addr: 2.0.7
proxy-addr: 2.0.8
qs: 6.16.0
range-parser: 1.2.1
router: 2.2.0
@@ -13794,7 +13795,7 @@ snapshots:
property-information@7.1.0: {}
proxy-addr@2.0.7:
proxy-addr@2.0.8:
dependencies:
forwarded: 0.2.0
ipaddr.js: 1.9.1
+5
View File
@@ -107,6 +107,11 @@ overrides:
"mermaid": "11.16.1"
# body-parser (via express): invalid `limit` silently disabled size enforcement.
"body-parser": "2.3.0"
# proxy-addr (via @modelcontextprotocol/sdk > express): GHSA-jqcg-44mw-7w3h
# (critical), a short IPv4-mapped IPv6 trust subnet trusts every client, so
# `req.ip` returns a spoofed X-Forwarded-For. 2.0.8 (2026-09-15) clears the
# 7-day cooldown gate.
"proxy-addr": "2.0.8"
# @humanfs/node (via eslint): recursive copy followed symlinks outside the tree.
"@humanfs/node": "0.16.8"
# js-yaml: quadratic CPU in `!!omap` resolution (CVE-2026-59870 not backported