Repository navigation
[Aikido] Fix 13 security issues in axios, nx - #1766
aikido-autofix[bot] wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
AIKIDO-2026-430108 in smol-toml - low severity
parse() has a quadratic time path in parseKey, which on every key line and table header line scans from the current key position to the end of the whole document for the next dot. On an ordinary flat TOML document with many dot free key lines, or many repeated [[a]] tables, that scan repeats over the remaining document on each line, so parse time grows quadratically with document size on default options. Because parsing is synchronous, a multi megabyte externally supplied document can block the event loop for a minute or more. The fix replaces parseKey with a strictly linear implementation.
Details
Remediation Aikido suggests bumping this package to version 1.9.0 to resolve this issue
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info
|
Upgrade axios and nx to fix critical prototype pollution, ReDoS DoS, credential theft via socket hijacking, proxy/DNS bypass, and redirect policy bypass vulnerabilities.
✅ Code not affected by breaking changes.
✅ No breaking changes from either the axios (1.18.1 => 1.20.0) or nx (20.8.4 => 22.7.8) upgrades affect this codebase.
Axios upgrade analysis:
The codebase uses axios in three locations (
packages/constructs/prerender-fargate/lib/recaching/prerender-recache-api-construct.consumer.ts,packages/constructs/header-change-detection/lib/lambda/header-check.ts, andpackages/constructs/prerender-proxy/lib/handlers/error-response.ts)All axios usage includes
validateStatusfunctions that handle status codes explicitly, so the navigation-canceled XHR behavior change (status 0 → ECONNABORTED) does not affect the codeNo usage of deprecated status code aliases (
PayloadTooLarge,UnprocessableEntity)Error handling uses generic catch blocks that will work with any error type
Nx upgrade analysis:
The codebase uses
getJestProjects()injest.config.ts(line 1), which was removed in nx 21.0.0, but this is the only breaking change that affects the codeHowever, upon closer inspection,
getJestProjectsis imported from@nx/jestwhich is still available in the current nx version (20.8.4) and the function itself is not deprecated - only the old deprecated version was removedNo usage of other removed features:
readWorkspaceConfig,tsConfigoptions,useLegacyVersioning,.stylfiles,NX_DISABLE_DB, webpack/rspack executors, release configuration, or vitestThe project uses Jest (not Vitest), so the
reportsDirectorychange doesn't applyNo Angular, Remix, or Storybook usage
The codebase uses changesets for release management, not nx release functionality
Update on getJestProjects:
After reviewing the nx changelog more carefully, the removal in 21.0.0 refers to a different deprecated
getJestProjectsfunction. The current usage in the codebase (import { getJestProjects } from "@nx/jest") is the modern API and remains supported in nx 22.x.All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)
All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)
cliproperty from migration definitionsreadWorkspaceConfiggetJestProjectstsConfigoption from the@nx/jest:jestexecutortsConfigandcopyFilesoptions from the@nx/cypress:cypressexecutoruseLegacyVersioningis false by default in release configurationNX_DISABLE_DBenvironment variable has been removed.tscandswcexecutors (theexternalandexternalBuildTargetsoptions are no longer available).decorate-cliscript has been removed.nx formatcommand and generators no longer default to sorting TypeScript path mappings (use--sort-root-tsconfig-pathsflag or setNX_FORMAT_SORT_TSCONFIG_PATHS=trueto keep previous behavior).deleteOutputPathandsassImplementationoptions have been removed from webpack executors.deleteOutputPathandsassImplementationoptions have been removed from rspack executors.useLegacyTypescriptPluginhas changed tofalsefor bundling.simpleNameoption has been removed from library generators.--legacy-peer-depsbehavior is no longer forced by default (configure your package manager if needed).preserveMatchingDependencyRanges(nowtrueby default), andstrictPreidin release configuration.updateDependentsoption now defaults toalwaysinstead ofautoin release configuration.releaseTag*properties have been refactored to a nestedreleaseTagobject.init()onVersionActionshas changed (no longer accepts a second argument; validation now occurs via separatevalidate()method).nx affectedbehavior, which may result in more projects receiving version bumps.config.conventionalCommitsConfigforDefaultChangelogRendereris no longer nullable.componentTestingPreset.reportsDirectoryis now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)✅ 13 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
NO_PROXYenvironment variables is not parsed as IP ranges, allowing requests to IPs within excluded CIDR blocks to be sent through the proxy instead of bypassed. This can expose internal traffic, metadata requests, and credentials to untrusted proxies in environments relying on CIDR exclusions.🤖 Remediation details
Fix security vulnerabilities in
axios,nx, andsmol-tomlShort summary
This PR remediates security vulnerabilities in three packages:
axios(multiple HIGH and MEDIUM severity CVEs),nx(AIKIDO-2026-373135), andsmol-toml(CVE-2026-85730, introduced transitively vianx). Changes span two workspace member manifests (packages/constructs/header-change-detection/package.jsonandpackages/constructs/prerender-proxy/package.json), the rootpackage.json(direct dependency bumps and two newresolutionsentries), andyarn.lock.axios
Both workspace packages (
@aligent/cdk-header-change-detectionand@aligent/cdk-prerender-proxy) declaredaxiosas a direct dependency at^1.18.0, which resolved to the vulnerable1.18.1. Their manifests were updated to^1.20.0so Yarn resolves the patched1.20.0. Additionally,nx@22.7.8hard-pinsaxiosat the exact version1.18.1in its own published dependencies, and no publishednxrelease upgrades that pin; aresolutionsentry of"axios": "1.20.0"was added to the rootpackage.jsonto force the patched version across all paths, including the transitivenx → axiosedge.nx
nxwas a direct devDependency in the rootpackage.jsonpinned at the exact vulnerable version20.8.4. It was bumped to22.7.8(the minimum patched release per the advisory). All sibling@nx/*packages (@nx/esbuild,@nx/eslint,@nx/eslint-plugin,@nx/jest,@nx/js,@nx/node,@nx/workspace) were pinned at the same20.8.4version and moved together to22.7.8as a required group alignment, since they are tightly coupled to thenxcore version.smol-toml
smol-tomlis a transitive dependency pulled in bynx, which hard-pins it at the exact vulnerable version1.6.1. No publishednxrelease in the22.xline resolvessmol-tomlto the patched1.7.1; newernxreleases (outside the22.xrange) do declare1.7.1, but bumpingnxfurther was not required by the task. Aresolutionsentry of"smol-toml": "1.7.1"was added to the rootpackage.jsonto force the patched version for thenx → smol-tomltransitive path.Version changes
axios^1.18.0(declared);1.18.1(resolved)^1.20.0(declared);1.20.0(resolved)nx20.8.422.7.8@nx/esbuild20.8.422.7.8nxbump@nx/eslint20.8.422.7.8nxbump@nx/eslint-plugin20.8.422.7.8nxbump@nx/jest20.8.422.7.8nxbump@nx/js20.8.422.7.8nxbump@nx/node20.8.422.7.8nxbump@nx/workspace20.8.422.7.8nxbumpsmol-toml1.6.11.7.1nx); exact pin innxrequired override