Skip to content

Security: patch CVE batch (composer, openssl, npm bundles, util-linux) + fpm healthcheck hardening - #113

Merged
MattGrundy merged 2 commits into
mainfrom
mg/update
Sep 8, 2026
Merged

MattGrundy merged 2 commits into
mainfrom
mg/update

Conversation

@MattGrundy

Copy link
Copy Markdown
Contributor
  • harden fpm healthcheck with bounded retry
  • fix(security): patch composer, openssl, npm bundles and util-linux CVEs

MattGrundy and others added 2 commits August 27, 2026 15:33
Aikido batch (2026-09):
- composer 2.9.7 -> 2.10.3 (CVE-2026-84361 cmd injection, CVE-2026-45793)
- openssl/libssl3t64/openssl-provider-legacy 3.5.6 -> 3.5.7-1~deb13u2 (CVE-2026-63072 RCE, CVE-2026-63076, CVE-2026-18798)
- npm-bundled ip-address 10.3.1 -> 10.6.0 (SSRF: GHSA-2vr4-cq9g-pvrc, GHSA-rpw4-54j3-4h4q)
- npm-bundled undici 7.24.1 -> 8.10.2 (CVE-2026-12151 DoS, CVE-2026-9679 CRLF, infinite-loop DoS)
- util-linux stack -> 2.41.5-0+deb13u1 via scoped --only-upgrade (CVE-2026-53612/53613/53614/53615)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@MattGrundy
MattGrundy merged commit 525d52c into main Sep 8, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants