[Aikido] Fix 19 security issues in fast-xml-parser, fast-uri, aws-cdk-lib and 5 more - #43
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
Conversation
Package lock diff2.4.1 -> 2.6.1 node_modules/@aws-cdk/asset-awscli-v1 2.2.242 -> 2.2.282 node_modules/@aws-cdk/asset-node-proxy-agent-v6 2.1.0 -> 2.1.2 node_modules/@aws-cdk/cloud-assembly-schema 45.2.0 -> 54.8.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/jsonschema 1.4.1 -> 1.5.0 node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver 7.7.2 -> 7.8.4 node_modules/@aws-crypto/sha256-browser removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-utf8 removed node_modules/@aws-crypto/sha256-js removed node_modules/@aws-crypto/supports-web-crypto removed node_modules/@aws-crypto/util removed node_modules/@aws-crypto/util/node_modules/@smithy/is-array-buffer removed node_modules/@aws-crypto/util/node_modules/@smithy/util-buffer-from removed node_modules/@aws-crypto/util/node_modules/@smithy/util-utf8 removed node_modules/@aws-sdk/client-cognito-identity 3.840.0 -> 3.1078.0 node_modules/@aws-sdk/client-secrets-manager 3.840.0 -> 3.1078.0 node_modules/@aws-sdk/client-sso removed node_modules/@aws-sdk/core 3.840.0 -> 3.974.26 node_modules/@aws-sdk/credential-provider-cognito-identity 3.840.0 -> 3.972.51 node_modules/@aws-sdk/credential-provider-env 3.840.0 -> 3.972.52 node_modules/@aws-sdk/credential-provider-http 3.840.0 -> 3.972.54 node_modules/@aws-sdk/credential-provider-ini 3.840.0 -> 3.972.59 node_modules/@aws-sdk/credential-provider-node 3.840.0 -> 3.972.61 node_modules/@aws-sdk/credential-provider-process 3.840.0 -> 3.972.52 node_modules/@aws-sdk/credential-provider-sso 3.840.0 -> 3.972.58 node_modules/@aws-sdk/credential-provider-web-identity 3.840.0 -> 3.972.58 node_modules/@aws-sdk/credential-providers 3.840.0 -> 3.1078.0 node_modules/@aws-sdk/middleware-host-header removed node_modules/@aws-sdk/middleware-logger removed node_modules/@aws-sdk/middleware-recursion-detection removed node_modules/@aws-sdk/middleware-user-agent removed node_modules/@aws-sdk/nested-clients 3.840.0 -> 3.997.26 node_modules/@aws-sdk/region-config-resolver removed node_modules/@aws-sdk/token-providers 3.840.0 -> 3.1078.0 node_modules/@aws-sdk/types 3.840.0 -> 3.973.15 node_modules/@aws-sdk/util-endpoints removed node_modules/@aws-sdk/util-locate-window removed node_modules/@aws-sdk/util-user-agent-browser removed node_modules/@aws-sdk/util-user-agent-node removed node_modules/@aws-sdk/xml-builder 3.821.0 -> 3.972.33 node_modules/@smithy/abort-controller removed node_modules/@smithy/config-resolver removed node_modules/@smithy/core 3.6.0 -> 3.29.0 node_modules/@smithy/credential-provider-imds 4.0.6 -> 4.4.5 node_modules/@smithy/fetch-http-handler 5.0.4 -> 5.6.2 node_modules/@smithy/hash-node removed node_modules/@smithy/invalid-dependency removed node_modules/@smithy/is-array-buffer removed node_modules/@smithy/middleware-content-length removed node_modules/@smithy/middleware-endpoint removed node_modules/@smithy/middleware-retry removed node_modules/@smithy/middleware-serde removed node_modules/@smithy/middleware-stack removed node_modules/@smithy/node-config-provider removed node_modules/@smithy/node-http-handler 4.0.6 -> 4.9.2 node_modules/@smithy/property-provider removed node_modules/@smithy/protocol-http removed node_modules/@smithy/querystring-builder removed node_modules/@smithy/querystring-parser removed node_modules/@smithy/service-error-classification removed node_modules/@smithy/shared-ini-file-loader removed node_modules/@smithy/signature-v4 5.1.2 -> 5.6.1 node_modules/@smithy/smithy-client removed node_modules/@smithy/types 4.3.1 -> 4.15.1 node_modules/@smithy/url-parser removed node_modules/@smithy/util-base64 removed node_modules/@smithy/util-body-length-browser removed node_modules/@smithy/util-body-length-node removed node_modules/@smithy/util-buffer-from removed node_modules/@smithy/util-config-provider removed node_modules/@smithy/util-defaults-mode-browser removed node_modules/@smithy/util-defaults-mode-node removed node_modules/@smithy/util-endpoints removed node_modules/@smithy/util-hex-encoding removed node_modules/@smithy/util-middleware removed node_modules/@smithy/util-retry removed node_modules/@smithy/util-stream removed node_modules/@smithy/util-uri-escape removed node_modules/@smithy/util-utf8 removed node_modules/@types/uuid removed node_modules/ajv 6.12.6 -> 6.15.0 node_modules/aws-cdk-lib 2.204.0 -> 2.260.0 node_modules/aws-cdk-lib/node_modules/ajv 8.17.1 -> 8.20.0 node_modules/aws-cdk-lib/node_modules/balanced-match 1.0.2 -> 4.0.4 node_modules/aws-cdk-lib/node_modules/brace-expansion 1.1.12 -> 5.0.6 node_modules/aws-cdk-lib/node_modules/concat-map removed node_modules/aws-cdk-lib/node_modules/fast-uri 3.0.6 -> 3.1.2 node_modules/aws-cdk-lib/node_modules/fs-extra 11.3.0 -> 11.3.5 node_modules/aws-cdk-lib/node_modules/jsonfile 6.1.0 -> 6.2.1 node_modules/aws-cdk-lib/node_modules/minimatch 3.1.2 -> 10.2.5 node_modules/aws-cdk-lib/node_modules/semver 7.7.2 -> 7.8.1 node_modules/aws-cdk-lib/node_modules/yaml 1.10.2 -> 1.10.3 node_modules/bowser 2.11.0 -> 2.14.1 node_modules/brace-expansion 1.1.12 -> 1.1.15 node_modules/constructs 10.4.2 -> 10.6.0 node_modules/fast-xml-parser removed node_modules/filelist/node_modules/brace-expansion 2.0.2 -> 2.1.1 node_modules/filelist/node_modules/minimatch 5.1.6 -> 5.1.9 node_modules/minimatch 3.1.2 -> 3.1.5 node_modules/strnum removed node_modules/uuid removed node_modules/@aws-sdk/credential-provider-login added node_modules/@aws-sdk/signature-v4-multi-region added node_modules/@aws/lambda-invoke-store added node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api added |
Author
|
Closed by Aikido: a new AutoFix has been created → #44 |
aikido-autofix
Bot
deleted the
fix/aikido-security-update-packages-60138086-jj77
branch
July 8, 2026 23:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade dependencies to fix critical XML entity injection XSS, XML entity expansion DoS attacks, stack overflow in XML builder, URI normalization bypass, and other security vulnerabilities.
All breaking changes by upgrading aws-cdk-lib from version 2.204.0 to 2.260.0 (CHANGELOG)
aws-cdk-lib.aws_ec2.CfnTrafficMirrorFilterRule:Idattribute was removedaws-cdk-lib.aws_kinesis.StreamConsumer:Idattribute was removedaws-cdk-lib.aws_neptune.DBInstance:Idattribute was removedaws-opsworkscm: CfnServer resource is no longer provisionable (AWS::OpsWorksCM::Server). Service is on deprecation pathaws-iotfleetwise: PropertiesDataDestinationConfigs,SignalsToCollectandSignalsToFetchin resourceCfnCampaignare now marked as immutable (they will cause a replacement of the resource if updated)aws-rds: AWS::RDS::DBInstance:StatusInfosproperty is removedaws-sagemaker: AWS::SageMaker::Domain:SingleSignOnApplicationArnproperty is removedaws-cloudfront: AWS::CloudFront::Function:Nameproperty is now set as immutableaws-ecs: AWS::ECS::Service: AvailabilityZoneRebalancing property default value changed from "ENABLED" to "DISABLED"aws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: PortfolioId property is now requiredaws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: PrincipalARN property is now requiredaws-servicecatalog: AWS::ServiceCatalog::PortfolioProductAssociation: Id attribute removedaws-neptune: AWS::Neptune::EventSubscription: SnsTopicArn property is now requiredaws-neptune: AWS::Neptune::EventSubscription: Id attribute removedaws-servicecatalog: AWS::ServiceCatalog::PortfolioShare: Id attribute removedaws-lex: AWS::Lex::ResourcePolicy: ResourceArn property is now immutableuseOptimalInstanceClassesaws-datazone: AWS::DataZone::ProjectProfile: Id property removedaws-logs: AWS::Logs::DeliveryDestination: DeliveryDestinationType attribute removedaws-s3: AWS::S3::AccessGrantsLocation: IamRoleArn property is now requiredaws-s3: AWS::S3::AccessGrantsLocation: LocationScope property is now requiredaws-servicecatalog: AWS::ServiceCatalog::TagOptionAssociation: Id attribute removedRuntimeAuthorizerConfiguration.usingCognito()has changed to accept IUserPool and IUserPoolClient constructs instead of string parameters, and now supports multiple clientsaws-dynamodb: AWS::DynamoDB::GlobalTable: GlobalTableSettingsReplicationMode property removedaws-dynamodb: AWS::DynamoDB::GlobalTable: GlobalTableSourceArn property removedaws-dynamodb: AWS::DynamoDB::Table: GlobalTableSettingsReplicationMode property removedaws-events: AWS::Events::EventBusPolicy: Id attribute removedIBucketRef,IRoleRef,etc.) were moved to a newaws-cdk-lib.interfacessubmodule to prevent cyclic dependencies between service modulesaws-opensearchserverless: AWS::OpenSearchServerless::Collection: StandbyReplicas property is now immutableaws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: Id attribute removedaws-dynamodb: AWS::DynamoDB::GlobalTable: ResourcePolicy property is now requiredaws-backup: AWS::Backup::LogicallyAirGappedBackupVault: EncryptionKeyArn attribute removedAWS::EC2::EC2FleetpropertiesDefaultTargetCapacityTypeandTargetCapacityUnitTypeare now immutable.lifecycleConfigurationwith default values when not explicitly specified by users.engineproperty inNoPasswordUserPropshas been removed.JobQueue.computeEnvironmentsproperty now containscomputeEnvironment: IComputeEnvironment → IComputeEnvironmentRef, requiring casting for fewer guarantees.BackupPlanRule.propsproperty now containsbackupVault: IBackupVault → IBackupVaultRef, requiring casting for fewer guarantees.AWS::SecurityHub::ConnectorV2includingProvider.JiraCloud.AuthStatus,Provider.JiraCloud.AuthUrl,Provider.JiraCloud.CloudId,Provider.JiraCloud.Domain,Provider.ServiceNow.AuthStatus, and typesJiraCloudandServiceNow.AWS::SSM::MaintenanceWindowTargetattributeIdremoved.AWS::ECS::CapacityProviderpropertyManagedInstancesNetworkConfiguration.SecurityGroupsis now required.securityGroupsis now required inManagedInstancesCapacityProviderProps.JobQueue.computeEnvironments,BackupPlanRule.props,ApiDestination.fromApiDestinationAttributes()return type, and others now use reference interfaces instead of concrete types.ApiDestination.fromApiDestinationAttributes()now returnsIApiDestinationinstead ofApiDestination;EventDestination.buschanged fromIEventBustoIEventBusRef.FlowLogDestination.bind()andICluster.executeCommandConfigurationnow containILogGroupRefinstead ofILogGroup.enableBatchConfigproperty is explicitly disabled by default.IEncryptedResourcenow extendsIEnvironmentAwareinstead ofIResource. Receivers have fewer guarantees about object shape and may need type guards or casting.IGatewayrequiresgatewayRef,IGatewayTargetrequiresgatewayTargetRef,IMemoryrequiresmemoryRef,IBedrockAgentRuntimerequiresruntimeRef,IRuntimeEndpointrequiresruntimeEndpointRef,IBrowserCustomrequiresbrowserCustomRef,ICodeInterpreterCustomrequirescodeInterpreterCustomRef.AWS::LicenseManager::LicensepropertiesBeneficiaryandProductSKUare now required.AWS::SageMaker::ClusterpropertyOrchestrator.Eksis now immutable.AWS::CodeDeploy::DeploymentGroupattributeIdremoved.AWS::SSM::MaintenanceWindowattributeIdremoved.AWS::BedrockAgentCore::OnlineEvaluationConfigattributeExecutionStatusremoved.AWS::AppStream::ImageBuilderpropertyNameis now immutable.AWS::EKS::Capabilityvended log typeEKS_CAPABILITY_ACK_S3_LOGSremoved.AWS::AppStream::StackattributeIdremoved.AWS::AppSync::GraphQLApipropertiesLogConfig.CloudWatchLogsRoleArnandLogConfig.FieldLogLevelare now required.AWS::KafkaConnect::ConnectorpropertyProvisionedCapacity.McuCountis now required.AWS::EMR::ClusterpropertyMonitoringConfigurationand typesCloudWatchLogConfiguration,EMRConfiguration, andMonitoringConfigurationremoved.✅ 19 CVEs resolved by this upgrade, including 1 critical 🚨 CVE
This PR will resolve the following CVEs:
preserveOrder:truecauses stack overflow leading to denial of service when processing certain inputs. The application crashes due to improper recursion handling during XML construction.*()and+()) generate regexps with catastrophic backtracking, causing severe ReDoS denial-of-service attacks with minimal input patterns triggering multi-second hangs.🤖 Remediation details
Fix security vulnerabilities in fast-xml-parser, fast-uri, aws-cdk-lib, brace-expansion, yaml, minimatch, @smithy/config-resolver, and ajv
Short summary
This PR remediates security vulnerabilities in eight npm packages: fast-xml-parser, fast-uri, aws-cdk-lib, brace-expansion, yaml, minimatch, @smithy/config-resolver, and ajv. Three direct dependencies in the root
package.jsonwere bumped (aws-cdk-lib,@aws-sdk/client-secrets-manager,@aws-sdk/credential-providers) to pull in fixed transitive versions; remaining transitive instances were updated via lockfile-onlynpm updatecommands. All changes are reflected inpackage-lock.json.fast-xml-parser
Previously resolved at
4.4.1as a transitive dependency of@aws-sdk/core, which exact-pinned that version. Bumping@aws-sdk/client-secrets-managerand@aws-sdk/credential-providersto^3.844.0inpackage.jsoncaused npm to resolve@aws-sdk/coreat a version that no longer carries a root-levelfast-xml-parserentry, eliminating the vulnerable instance entirely. The parent bump was necessary because@aws-sdk/coreused an exact pin that blocked any lockfile-only update.fast-uri
Resolved at
3.0.6as a transitive dependency nested underaws-cdk-lib's own copy ofajv. Bumpingaws-cdk-libto^2.260.0inpackage.jsonbrought in a newerajv(8.20.0) that declaresfast-uri@^3.0.1, allowing resolution up to3.1.2. A full fix to3.1.3could not be achieved: the instance is deeply nested insideaws-cdk-lib's bundled subtree andnpm updateas well as multiple override shapes all failed to advance it beyond3.1.2in the virtual lockfile tree.aws-cdk-lib
A direct dependency in
package.json, bumped from^2.78.0to^2.260.0to address vulnerabilities inaws-cdk-libitself. This single manifest edit also resolved the nested vulnerable instances ofyaml,minimatch,brace-expansion,ajv(8.x), andfast-urithat are carried insideaws-cdk-lib's own dependency subtree, since those are all governed by the version ofaws-cdk-libthat npm resolves.brace-expansion
Resolved at
1.1.12(root, viaminimatch@3.x) and2.0.2(viafilelist'sminimatch@5.x). Both instances were updated vianpm update brace-expansion --package-lock-onlyafter the parentminimatchinstances were themselves refreshed; the^1.1.7and^2.0.1ranges declared by their respectiveminimatchparents already permitted the patched versions, so no manifest edit was required. Theaws-cdk-lib-nested instance moved to5.0.6as a side-effect of theaws-cdk-libbump.yaml
Resolved at
1.10.2as a transitive dependency exact-pinned byaws-cdk-lib@2.204.0. Bumpingaws-cdk-libto^2.260.0inpackage.jsoncaused npm to resolveaws-cdk-lib@2.260.0, which exact-pinsyaml@1.10.3, directly satisfying the patched version requirement without any additional lockfile-only step.minimatch
Resolved at
3.1.2in three separate instances (root hoisted,aws-cdk-libnested,filelistnested). Theaws-cdk-lib-nested instance was resolved to10.2.5as a side-effect of theaws-cdk-libbump (that version ofaws-cdk-libdeclaresminimatch@^10.2.5). The root andfilelistinstances were advanced to3.1.5and5.1.9respectively vianpm update minimatch --package-lock-only, which was sufficient because their parent packages (@eslint/eslintrc,eslint,filelist, etc.) all declare caret ranges that already permitted the patched versions.@smithy/config-resolver
Resolved at
4.1.4as a transitive dependency shared across multiple@aws-sdkpackages. Bumping@aws-sdk/client-secrets-managerand@aws-sdk/credential-providersto^3.844.0inpackage.jsoncaused npm to resolve those packages at versions that declare@smithy/config-resolver@^4.1.4, a range that permits4.4.0+. A subsequentnpm update @smithy/config-resolver --package-lock-onlyrefreshed the lockfile entry to the patched version.ajv
Present in two instances:
6.12.6(root, pulled in byeslintand@eslint/eslintrc) and8.17.1(nested underaws-cdk-lib'stabledependency). The8.xinstance was advanced to8.20.0as a side-effect of theaws-cdk-libbump. The6.xinstance was advanced to6.15.0vianpm update ajv --package-lock-only; the parenteslint@8.57.1already declaresajv@^6.12.4, which permits6.14.0+, so no manifest edit was needed.Version changes
aws-cdk-lib^2.78.0(resolved2.204.0)^2.260.0(resolved2.260.0)@aws-sdk/client-secrets-manager^3.348.0(resolved3.840.0)^3.844.0(resolved3.1078.0)@aws-sdk/credential-providers^3.348.0(resolved3.840.0)^3.844.0(resolved3.1078.0)yaml(aws-cdk-lib nested)1.10.21.10.3minimatch(aws-cdk-lib nested)3.1.210.2.5minimatch(root)3.1.23.1.5minimatch(filelist nested)5.1.65.1.9brace-expansion(root)1.1.121.1.15brace-expansion(filelist nested)2.0.22.1.1brace-expansion(aws-cdk-lib nested)1.1.125.0.6ajv(root)6.12.66.15.0ajv(aws-cdk-lib nested)8.17.18.20.0fast-uri(aws-cdk-lib/ajv nested)3.0.63.1.2fast-xml-parser(root)4.4.1@smithy/config-resolver(root)4.1.4@aws-sdk/core3.840.03.974.26