Skip to content

fix(deps): Patch undici WebSocket denial of service - #156

Merged
sds merged 1 commit into
mainfrom
centaur/fix-undici-websocket-dos-1790652296
Sep 29, 2026
Merged

sds merged 1 commit into
mainfrom
centaur/fix-undici-websocket-dos-1790652296

Conversation

@decofe

@decofe decofe commented Sep 29, 2026

Copy link
Copy Markdown
Member

Upgrade the direct undici dependency from 8.9.0 to 8.10.2 and regenerate the lockfile. This addresses GHSA-3wwx-pv8p-q78v, a process crash caused by malformed compressed WebSocket messages, and Dependabot alerts #55 and #56.

Validation:

  • Frozen-lockfile install, lint, application and test type checks, build, and formatting of the changed package manifest passed.
  • Unit suite: 226 passed, 19 failed because the sandbox lacks the sqlite3 executable. A clean base worktree with undici 8.9.0 reproduces all 14 failures in the four sampled failing suites.
  • The repository-wide format check flags the unchanged immutable-release friction entry. No source or test behavior is changed by this PR.

Prompted by: @sds

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedundici@​8.9.0 ⏵ 8.10.293100 +2100 +198100

View full report

sds added a commit that referenced this pull request Sep 29, 2026
CI dependency installation fails because Aegis rejects `tar@7.5.16` with
`criticalCVE`, as seen in [PR #156's failed
install](https://github.com/tempoxyz/wallet-cli/actions/runs/36517287127/job/109242311912).
The installed version is affected by [CVE-2026-59873 /
GHSA-23hp-3jrh-7fpw](GHSA-23hp-3jrh-7fpw),
which permits resource exhaustion while extracting archives.

Pin the transitive tar dependency to 7.5.22 and regenerate the lockfile.
This version also covers the newer
[GHSA-r292-9mhp-454m](GHSA-r292-9mhp-454m)
fix. The dependency comes from the development-only `@yao-pkg/pkg`
packager, which uses tar to extract downloaded Node.js archives. Include
a non-release changelog entry for this toolchain update.

This PR targets main independently of
[#156](#156); merge this
first, then update that PR from main. Existing security enforcement is
unchanged.

Validation:
- Frozen-lockfile install and dependency tree check: only tar 7.5.22
resolves.
- Lint, application/test type checks, TypeScript build, CLI bundle,
changed-file formatting, and changelog validation passed.
- Created and extracted a small gzip archive using tar resolved through
the packager; content matched.
- Full unit tests and standalone binary generation were not rerun. The
prior unit run was limited by the sandbox's missing sqlite3 executable.
The CLI bundle retains its existing import.meta/CommonJS warning.
- The live Aegis-protected CI install must confirm the policy block is
cleared.

Prompted by: @sds

Co-authored-by: Shane da Silva <677877+sds@users.noreply.github.com>
Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@decofe
decofe force-pushed the centaur/fix-undici-websocket-dos-1790652296 branch from cb89ace to 794f188 Compare September 29, 2026 03:44
@sds
sds merged commit 033d56c into main Sep 29, 2026
8 of 9 checks passed
@sds
sds deleted the centaur/fix-undici-websocket-dos-1790652296 branch September 29, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants