Skip to content

Commit d326414

Browse files
cortinicofacebook-github-bot
authored andcommitted
Fix security vulnerabilities in transitive dependencies
Summary: Add yarn resolutions and update lockfiles to fix security vulnerabilities in five transitive dependencies: - `xmldom/xmldom` 0.8.10 → 0.8.13 (CVE-2026-41672, XML injection) - `fast-xml-parser` 4.5.4 → 4.5.6 (CVE-2026-33349, CVE-2026-33036, entity expansion bypass) - `yaml` 2.5.0/2.8.1 → 2.9.0 (CVE-2026-33532, stack overflow via deep nesting) - `fast-uri` 3.0.6 → 3.1.2 (CVE-2026-6322, host confusion; CVE-2026-6321, path traversal) - `addressable` 2.8.5/2.8.7 → 2.9.0 (CVE-2026-35611, ReDoS) All bumps are within semver range of their parent constraints and are patch or minor version updates. - Fixes #56364 - Fixes #56365 - Fixes #56570 - Fixes #56393 - Fixes #56231 - Fixes #56741 Changelog: [General][Security] - Fix security vulnerabilities in `xmldom/xmldom`, `fast-xml-parser`, `yaml`, `fast-uri`, and `addressable` transitive dependencies Differential Revision: D107405946
1 parent 3fd8e9b commit d326414

4 files changed

Lines changed: 25 additions & 26 deletions

File tree

Gemfile.lock

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ GEM
88
i18n (>= 1.6, < 2)
99
minitest (>= 5.1)
1010
tzinfo (~> 2.0)
11-
addressable (2.8.5)
12-
public_suffix (>= 2.0.2, < 6.0)
11+
addressable (2.9.0)
12+
public_suffix (>= 2.0.2, < 8.0)
1313
algoliasearch (1.27.5)
1414
httpclient (~> 2.8, >= 2.8.3)
1515
json (>= 1.5.1)

package.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,10 @@
125125
"compression": "1.8.1",
126126
"@microsoft/api-extractor/minimatch": "3.1.4",
127127
"metro-babel-register/babel-plugin-syntax-hermes-parser": "0.36.1",
128-
"lodash": "4.18.1"
128+
"lodash": "4.18.1",
129+
"@xmldom/xmldom": "^0.8.13",
130+
"fast-xml-parser": "^4.5.6",
131+
"yaml": "^2.9.0",
132+
"fast-uri": "^3.1.2"
129133
}
130134
}

private/helloworld/Gemfile.lock

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ GEM
1010
i18n (>= 1.6, < 2)
1111
minitest (>= 5.1)
1212
tzinfo (~> 2.0)
13-
addressable (2.8.7)
14-
public_suffix (>= 2.0.2, < 7.0)
13+
addressable (2.9.0)
14+
public_suffix (>= 2.0.2, < 8.0)
1515
algoliasearch (1.27.5)
1616
httpclient (~> 2.8, >= 2.8.3)
1717
json (>= 1.5.1)

yarn.lock

Lines changed: 16 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -2584,10 +2584,10 @@
25842584
resolved "https://registry.yarnpkg.com/@vscode/sudo-prompt/-/sudo-prompt-9.3.1.tgz#c562334bc6647733649fd42afc96c0eea8de3b65"
25852585
integrity sha512-9ORTwwS74VaTn38tNbQhsA5U44zkJfcb0BdTSyyG6frP4e8KMtHuTXYmwefe5dpL8XB1aGSIVTaLjD3BbWb5iA==
25862586

2587-
"@xmldom/xmldom@^0.8.8":
2588-
version "0.8.10"
2589-
resolved "https://registry.yarnpkg.com/@xmldom/xmldom/-/xmldom-0.8.10.tgz#a1337ca426aa61cef9fe15b5b28e340a72f6fa99"
2590-
integrity sha512-2WALfTl4xo2SkGCYRt6rDTFfk9R1czmBvUQy12gK2KuRKIpWEhcbbzy8EZXtz/jkRqHX8bFEc6FC1HjX4TUWYw==
2587+
"@xmldom/xmldom@^0.8.13", "@xmldom/xmldom@^0.8.8":
2588+
version "0.8.13"
2589+
resolved "https://registry.yarnpkg.com/@xmldom/xmldom/-/xmldom-0.8.13.tgz#00d1dd940b218dff2e49309d410d8bb212159225"
2590+
integrity sha512-KRYzxepc14G/CEpEGc3Yn+JKaAeT63smlDr+vjB8jRfgTBBI9wRj/nkQEO+ucV8p8I9bfKLWp37uHgFrbntPvw==
25912591

25922592
abort-controller@^3.0.0:
25932593
version "3.0.0"
@@ -4643,15 +4643,15 @@ fast-levenshtein@^2.0.6:
46434643
resolved "https://registry.yarnpkg.com/fast-levenshtein/-/fast-levenshtein-2.0.6.tgz#3d8a5c66883a16a30ca8643e851f19baa7797917"
46444644
integrity sha512-DCXu6Ifhqcks7TZKY3Hxp3y6qphY5SJZmrWMDrKcERSOXWQdMhU9Ig/PYrzyw/ul9jOIyh0N4M0tbC5hodg8dw==
46454645

4646-
fast-uri@^3.0.1:
4647-
version "3.0.6"
4648-
resolved "https://registry.yarnpkg.com/fast-uri/-/fast-uri-3.0.6.tgz#88f130b77cfaea2378d56bf970dea21257a68748"
4649-
integrity sha512-Atfo14OibSv5wAp4VWNsFYE1AchQRTv9cBGWET4pZWHzYshFSS9NQI6I57rdKn9croWVMbYFbLhJ+yJvmZIIHw==
4646+
fast-uri@^3.0.1, fast-uri@^3.1.2:
4647+
version "3.1.2"
4648+
resolved "https://registry.yarnpkg.com/fast-uri/-/fast-uri-3.1.2.tgz#8af3d4fc9d3e71b11572cc2673b514a7d1a8c8ec"
4649+
integrity sha512-rVjf7ArG3LTk+FS6Yw81V1DLuZl1bRbNrev6Tmd/9RaroeeRRJhAt7jg/6YFxbvAQXUCavSoZhPPj6oOx+5KjQ==
46504650

4651-
fast-xml-parser@^4.4.1:
4652-
version "4.5.4"
4653-
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-4.5.4.tgz#64e52ddf1308001893bd225d5b1768840511c797"
4654-
integrity sha512-jE8ugADnYOBsu1uaoayVl1tVKAMNOXyjwvv2U6udEA2ORBhDooJDWoGxTkhd4Qn4yh59JVVt/pKXtjPwx9OguQ==
4651+
fast-xml-parser@^4.4.1, fast-xml-parser@^4.5.6:
4652+
version "4.5.6"
4653+
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-4.5.6.tgz#4ff57d4aca13a2d11aa42ad460495cf00f32b655"
4654+
integrity sha512-Yd4vkROfJf8AuJrDIVMVmYfULKmIJszVsMv7Vo71aocsKgFxpdlpSHXSaInvyYfgw2PRuObQSW2GFpVMUjxu9A==
46554655
dependencies:
46564656
strnum "^1.0.5"
46574657

@@ -9661,15 +9661,10 @@ yallist@^4.0.0:
96619661
resolved "https://registry.yarnpkg.com/yallist/-/yallist-4.0.0.tgz#9bb92790d9c0effec63be73519e11a35019a3a72"
96629662
integrity sha512-3wdGidZyq5PB084XLES5TpOSRA3wjXAlIWMhum2kRcv/41Sn2emQ0dycQW4uZXLejwKvg6EsvbdlVL+FYEct7A==
96639663

9664-
yaml@^2.2.1:
9665-
version "2.5.0"
9666-
resolved "https://registry.yarnpkg.com/yaml/-/yaml-2.5.0.tgz#c6165a721cf8000e91c36490a41d7be25176cf5d"
9667-
integrity sha512-2wWLbGbYDiSqqIKoPjar3MPgB94ErzCtrNE1FdqGuaO0pi2JGjmE8aW8TDZwzU7vuxcGRdL/4gPQwQ7hD5AMSw==
9668-
9669-
yaml@^2.6.1:
9670-
version "2.8.1"
9671-
resolved "https://registry.yarnpkg.com/yaml/-/yaml-2.8.1.tgz#1870aa02b631f7e8328b93f8bc574fac5d6c4d79"
9672-
integrity sha512-lcYcMxX2PO9XMGvAJkJ3OsNMw+/7FKes7/hgerGUYWIoWu5j/+YQqcZr5JnPZWzOsEBgMbSbiSTn/dv/69Mkpw==
9664+
yaml@^2.2.1, yaml@^2.6.1, yaml@^2.9.0:
9665+
version "2.9.0"
9666+
resolved "https://registry.yarnpkg.com/yaml/-/yaml-2.9.0.tgz#78274afd93598a1dfdd6130df6a566defcbf9aa4"
9667+
integrity sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==
96739668

96749669
yargs-parser@^18.1.2:
96759670
version "18.1.3"

0 commit comments

Comments
 (0)