Skip to content

update serialize-javascript to 7.0.5 to address CVE-2026-34043#5873

Open
robandpdx wants to merge 1 commit intomochajs:mainfrom
robandpdx:upgrade-serialize-javascript
Open

update serialize-javascript to 7.0.5 to address CVE-2026-34043#5873
robandpdx wants to merge 1 commit intomochajs:mainfrom
robandpdx:upgrade-serialize-javascript

Conversation

@robandpdx
Copy link
Copy Markdown

PR Checklist

Overview

According to CVE-2026-34043 serialize-javascript < 7.0.5 is vulnerable to CPU Exhaustion Denial of Service via crafted array-like objects. This change upgrades the dependency serialize-javascript to version 7.0.5.

@linux-foundation-easycla
Copy link
Copy Markdown

CLA Not Signed

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 7, 2026

👋 Hi @robandpdx, thanks for the pull request! A scan flagged a concern with it. Could you please take a look?

[pr-task-completion] This PR's body is missing [x] checks on the following tasks from the PR template.

Repositories often provide a set of tasks that pull request authors are expected to complete. Those tasks should be marked as completed with a [x] in the pull request description. Please complete those tasks and mark the checks as [x] completed.

🗺️ This message was posted automatically by OctoGuide: a bot for GitHub repository best practices.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🚀 Feature: upgrade serialize-javascript dependency to address CVE-2026-34043

1 participant