Skip to content

Fix CVE-2026-22775: Update devalue to 5.6.2#63

Merged
cywf merged 2 commits intomainfrom
copilot/apply-patches-for-cve-2023-45219
Jan 16, 2026
Merged

Fix CVE-2026-22775: Update devalue to 5.6.2#63
cywf merged 2 commits intomainfrom
copilot/apply-patches-for-cve-2023-45219

Conversation

Copy link
Contributor

Copilot AI commented Jan 16, 2026

Addresses denial-of-service vulnerability in devalue where malicious inputs to devalue.parse can cause excessive CPU/memory consumption.

Changes

  • site/package.json: Added npm overrides to force devalue@^5.6.2
  • site/package-lock.json: Updated transitive dependency from 5.4.2 → 5.6.2

The devalue package is pulled in by astro@5.15.3. Using npm overrides ensures the patched version is used until astro updates its own dependency constraint.

References

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • telemetry.astro.build
    • Triggering command: /usr/local/bin/node node /home/REDACTED/work/FortiPath/FortiPath/site/node_modules/.bin/astro build (dns block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

Please review this CVE (GHSA-g2pg-6438-jwpf) and apply the necessary patches / updates to the codebase accordingly.


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Co-authored-by: cywf <100837335+cywf@users.noreply.github.com>
Copilot AI changed the title [WIP] Update codebase to address CVE-2023-45219 security vulnerabilities Fix CVE-2026-22775: Update devalue to 5.6.2 Jan 16, 2026
Copilot AI requested a review from cywf January 16, 2026 00:15
@cywf cywf marked this pull request as ready for review January 16, 2026 00:18
@cywf cywf merged commit e8b2cbb into main Jan 16, 2026
6 checks passed
@cywf cywf deleted the copilot/apply-patches-for-cve-2023-45219 branch January 16, 2026 00:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants