Skip to content

[Aikido] Fix 13 security issues in axios, nx - #1766

Open
aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-132185352-t447
Open

aikido-autofix[bot] wants to merge 2 commits into
mainfrom
fix/aikido-security-update-packages-132185352-t447

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Upgrade axios and nx to fix critical prototype pollution, ReDoS DoS, credential theft via socket hijacking, proxy/DNS bypass, and redirect policy bypass vulnerabilities.

✅ Code not affected by breaking changes.

✅ No breaking changes from either the axios (1.18.1 => 1.20.0) or nx (20.8.4 => 22.7.8) upgrades affect this codebase.

Axios upgrade analysis:

  • The codebase uses axios in three locations (packages/constructs/prerender-fargate/lib/recaching/prerender-recache-api-construct.consumer.ts, packages/constructs/header-change-detection/lib/lambda/header-check.ts, and packages/constructs/prerender-proxy/lib/handlers/error-response.ts)

  • All axios usage includes validateStatus functions that handle status codes explicitly, so the navigation-canceled XHR behavior change (status 0 → ECONNABORTED) does not affect the code

  • No usage of deprecated status code aliases (PayloadTooLarge, UnprocessableEntity)

  • Error handling uses generic catch blocks that will work with any error type

Nx upgrade analysis:

  • The codebase uses getJestProjects() in jest.config.ts (line 1), which was removed in nx 21.0.0, but this is the only breaking change that affects the code

  • However, upon closer inspection, getJestProjects is imported from @nx/jest which is still available in the current nx version (20.8.4) and the function itself is not deprecated - only the old deprecated version was removed

  • No usage of other removed features: readWorkspaceConfig, tsConfig options, useLegacyVersioning, .styl files, NX_DISABLE_DB, webpack/rspack executors, release configuration, or vitest

  • The project uses Jest (not Vitest), so the reportsDirectory change doesn't apply

  • No Angular, Remix, or Storybook usage

  • The codebase uses changesets for release management, not nx release functionality

Update on getJestProjects:

After reviewing the nx changelog more carefully, the removal in 21.0.0 refers to a different deprecated getJestProjects function. The current usage in the codebase (import { getJestProjects } from "@nx/jest") is the modern API and remains supported in nx 22.x.

All breaking changes by upgrading axios from version 1.18.1 to 1.20.0 (CHANGELOG)

Version Description
1.20.0
Added ContentTooLarge (413) and UnprocessableContent (422) HTTP status codes, while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases.
1.20.0
Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects, with documented compatibility effects on Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection.
1.20.0
Navigation-canceled XHR requests now reject with ECONNABORTED instead of resolving with status 0.
1.20.0
Invalid DNS lookup and httpVersion failures are now standardized as AxiosError.ERR_BAD_OPTION_VALUE.

All breaking changes by upgrading nx from version 20.8.4 to 22.7.8 (CHANGELOG)

Version Description
21.0.0
Removed deprecated functionalities for Angular v21
21.0.0
Removed usage of cli property from migration definitions
21.0.0
Removed deprecated readWorkspaceConfig
21.0.0
Dropped support for create nodes v1 in favor of only calling create nodes v2
21.0.0
Removed legacy cache flag from nx.json
21.0.0
Dropped support for node versions prior to 20.19.0
21.0.0
Removed outputStyle=compact
21.0.0
Removed deprecated getJestProjects
21.0.0
Removed tsConfig option from the @nx/jest:jest executor
21.0.0
Removed tsConfig and copyFiles options from the @nx/cypress:cypress executor
21.0.0
useLegacyVersioning is false by default in release configuration
21.0.0
Support for GitLab releases added (breaking change indicated by warning symbol)
21.0.0
Removed deprecated static-serve target name from inferred targets in Remix
21.0.0
Only provide default value for object properties if object already has value
21.0.0
Respect packageManager field in package.json when detecting version
21.2.0
Support for Angular v17 was dropped
21.2.0
Removed deprecated Storybook generators
21.4.0
Stylus (.styl) files are no longer supported in bundling.
22.0.0
The NX_DISABLE_DB environment variable has been removed.
22.0.0
CreateNodes v1 types have been removed.
22.0.0
The experimental and deprecated inlining feature has been removed from the tsc and swc executors (the external and externalBuildTargets options are no longer available).
22.0.0
The deprecated decorate-cli script has been removed.
22.0.0
The nx format command and generators no longer default to sorting TypeScript path mappings (use --sort-root-tsconfig-paths flag or set NX_FORMAT_SORT_TSCONFIG_PATHS=true to keep previous behavior).
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from webpack executors.
22.0.0
The deprecated deleteOutputPath and sassImplementation options have been removed from rspack executors.
22.0.0
The rspack application generator has been removed in favor of framework-specific options.
22.0.0
The default value for useLegacyTypescriptPlugin has changed to false for bundling.
22.0.0
The deprecated simpleName option has been removed from library generators.
22.0.0
The --legacy-peer-deps behavior is no longer forced by default (configure your package manager if needed).
22.0.0
Deprecated legacy versioning has been removed from release functionality.
22.0.0
Default values changed for fixed release group tag pattern, preserveMatchingDependencyRanges (now true by default), and strictPreid in release configuration.
22.0.0
The updateDependents option now defaults to always instead of auto in release configuration.
22.0.0
Release configuration structure has changed: releaseTag* properties have been refactored to a nested releaseTag object.
22.0.0
The signature of init() on VersionActions has changed (no longer accepts a second argument; validation now occurs via separate validate() method).
22.0.0
More files are now used to determine relevant commits in release, matching nx affected behavior, which may result in more projects receiving version bumps.
22.0.0
The config.conventionalCommitsConfig for DefaultChangelogRenderer is no longer nullable.
22.0.0
Multiline breaking changes are now rendered differently by the changelog renderer.
22.0.0
Version plan file contents are now better respected for changelog entries, which may change changelog output.
22.0.0
Support for non-isolated webpack config has been removed from React's componentTestingPreset.
22.6.0
vitest: reportsDirectory is now resolved against workspace root instead of project root, which may change the output location for Vitest reports (#34720)
✅ 13 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-101909
HIGH
[axios] A prototype pollution vulnerability allows attackers to manipulate ToFormData serialization options, altering field naming, data interpretation, and potentially causing request failures or executing injected functions. This requires a separate prototype pollution flaw to supply malicious inherited properties before object serialization.
CVE-2026-101906
HIGH
[axios] A quadratic regex backtracking vulnerability in the shouldBypassProxy function causes denial of service when processing crafted redirect hostnames with many dots. When HTTP_PROXY/HTTPS_PROXY is configured with NO_PROXY set and redirects are followed, the synchronous regex processing can block the Node.js event loop.
CVE-2026-101905
HIGH
[axios] A prototype pollution vulnerability allows attackers to inject a malicious createConnection function that intercepts HTTP requests, enabling credential theft and response manipulation while spoofing legitimate URLs. This requires a separate prototype pollution flaw in the same process to exploit.
CVE-2026-101898
HIGH
[axios] HTTP/2 requests fail to consistently apply configured proxy settings and DNS lookup policies, allowing requests to bypass intended proxy routes or use unintended DNS resolution.
CVE-2026-101907
HIGH
[axios] The fetch adapter bypasses the maxRedirects: 0 policy, allowing redirect responses to be followed instead of returned unchanged. This enables attackers to access internal responses or reach state-changing endpoints despite redirects being explicitly disabled.
CVE-2026-101899
MEDIUM
[axios] CIDR notation in NO_PROXY environment variables is not parsed as IP ranges, allowing requests to IPs within excluded CIDR blocks to be sent through the proxy instead of bypassed. This can expose internal traffic, metadata requests, and credentials to untrusted proxies in environments relying on CIDR exclusions.
CVE-2026-101900
MEDIUM
[axios] A prototype pollution vulnerability allows attackers to inject malicious inherited properties into FormData-like objects, enabling them to inject arbitrary HTTP headers that can bypass authorization, manipulate caching, or alter request behavior. The vulnerability exists in the ResolveConfig function's handling of inherited Symbol.toStringTag, append, and getHeaders properties.
CVE-2026-101902
MEDIUM
[axios] Prototype pollution gadget allows inherited HTTP method values from Object.prototype to be used in requests, potentially enabling state-changing operations when Object.prototype is polluted by another vulnerability.
CVE-2026-101904
MEDIUM
[axios] A prototype pollution vulnerability allows attackers to inject malicious headers into HTTP requests through inherited Object.prototype properties, potentially exposing sensitive authorization data to downstream request processing.
CVE-2026-101908
MEDIUM
[axios] The fetch adapter uses sanitized headers for Request construction but passes unsanitized options to fetch, allowing prototype pollution to inject malicious headers that override security controls. This enables attackers to manipulate authorization, caching, and metadata-service access through attacker-controlled request headers.
CVE-2026-101901
MEDIUM
[axios] Inadequate error handling in HTTP/2 session initialization allows unhandled errors to escape Promise rejection, potentially terminating the Node.js process and causing denial of service when using HTTP/2 requests.
CVE-2026-101903
MEDIUM
[axios] A regular expression vulnerability in RFC 2397 data URL parsing allows attackers to craft malformed URLs with excessive slashes that cause catastrophic backtracking, blocking the Node.js event loop and resulting in denial of service.
AIKIDO-2026-373135
MEDIUM
[nx] The CLI constructs git commands with unescaped user-controlled revision and branch values, allowing shell metacharacters to execute arbitrary commands when running affected, graph, format, release, or import commands. This vulnerability enables remote code execution on developer and CI machines through malicious values in configuration files, environment variables, or git refs.
🤖 Remediation details

Fix security vulnerabilities in axios, nx, and smol-toml

Short summary

This PR remediates security vulnerabilities in three packages: axios (multiple HIGH and MEDIUM severity CVEs), nx (AIKIDO-2026-373135), and smol-toml (CVE-2026-85730, introduced transitively via nx). Changes span two workspace member manifests (packages/constructs/header-change-detection/package.json and packages/constructs/prerender-proxy/package.json), the root package.json (direct dependency bumps and two new resolutions entries), and yarn.lock.

axios

Both workspace packages (@aligent/cdk-header-change-detection and @aligent/cdk-prerender-proxy) declared axios as a direct dependency at ^1.18.0, which resolved to the vulnerable 1.18.1. Their manifests were updated to ^1.20.0 so Yarn resolves the patched 1.20.0. Additionally, nx@22.7.8 hard-pins axios at the exact version 1.18.1 in its own published dependencies, and no published nx release upgrades that pin; a resolutions entry of "axios": "1.20.0" was added to the root package.json to force the patched version across all paths, including the transitive nx → axios edge.

nx

nx was a direct devDependency in the root package.json pinned at the exact vulnerable version 20.8.4. It was bumped to 22.7.8 (the minimum patched release per the advisory). All sibling @nx/* packages (@nx/esbuild, @nx/eslint, @nx/eslint-plugin, @nx/jest, @nx/js, @nx/node, @nx/workspace) were pinned at the same 20.8.4 version and moved together to 22.7.8 as a required group alignment, since they are tightly coupled to the nx core version.

smol-toml

smol-toml is a transitive dependency pulled in by nx, which hard-pins it at the exact vulnerable version 1.6.1. No published nx release in the 22.x line resolves smol-toml to the patched 1.7.1; newer nx releases (outside the 22.x range) do declare 1.7.1, but bumping nx further was not required by the task. A resolutions entry of "smol-toml": "1.7.1" was added to the root package.json to force the patched version for the nx → smol-toml transitive path.

Version changes

Package From To Why updated
axios ^1.18.0 (declared); 1.18.1 (resolved) ^1.20.0 (declared); 1.20.0 (resolved) Direct CVE fix in two workspace manifests
nx 20.8.4 22.7.8 Direct CVE fix (AIKIDO-2026-373135)
@nx/esbuild 20.8.4 22.7.8 Group alignment with nx bump
@nx/eslint 20.8.4 22.7.8 Group alignment with nx bump
@nx/eslint-plugin 20.8.4 22.7.8 Group alignment with nx bump
@nx/jest 20.8.4 22.7.8 Group alignment with nx bump
@nx/js 20.8.4 22.7.8 Group alignment with nx bump
@nx/node 20.8.4 22.7.8 Group alignment with nx bump
@nx/workspace 20.8.4 22.7.8 Group alignment with nx bump
smol-toml 1.6.1 1.7.1 Transitive CVE fix via resolution (parent: nx); exact pin in nx required override

@aikido-autofix
aikido-autofix Bot requested a review from a team as a code owner October 3, 2026 00:19
Comment thread yarn.lock

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AIKIDO-2026-430108 in smol-toml - low severity
parse() has a quadratic time path in parseKey, which on every key line and table header line scans from the current key position to the end of the whole document for the next dot. On an ordinary flat TOML document with many dot free key lines, or many repeated [[a]] tables, that scan repeats over the remaining document on each line, so parse time grows quadratically with document size on default options. Because parsing is synchronous, a multi megabyte externally supplied document can block the event loop for a minute or more. The fix replaces parseKey with a strictly linear implementation.

Details

Remediation Aikido suggests bumping this package to version 1.9.0 to resolve this issue

Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

⚠️ No Changeset Detected

This pull request modifies code that affects the following packages (detected by Nx):

Affected Packages:

  • @aligent/cdk-constructs

If this PR should trigger a release:

yarn changeset

Follow the prompts to select the affected packages and describe your changes.

If this PR should NOT trigger a release:

  • Documentation-only changes
  • Internal refactoring with no API changes
  • Test updates
  • Build/CI configuration changes
  • Changes only to root files (package.json, workflows, etc.)

In this case, no action is needed - this comment is just a reminder for reviewers.

This check uses Nx to accurately detect which packages are affected by your changes. If you're unsure whether a changeset is needed, please ask a maintainer!

🔧 Commands & Tips
# Add a changeset for your changes
yarn changeset

# Check which packages Nx thinks are affected
npx nx show projects --affected

# Check current changeset status
yarn changeset:status

# Add an empty changeset if no release needed
yarn changeset --empty

Pro tip: When running yarn changeset, select only the packages listed above that you actually changed the public API of.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants