Skip to content

[Security] Bump http-cache-semantics from 4.1.0 to 4.1.1

Bumps http-cache-semantics from 4.1.0 to 4.1.1. This update includes a security fix.

Vulnerabilities fixed

http-cache-semantics vulnerable to Regular Expression Denial of Service http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

Patched versions: 4.1.1 Affected versions: < 4.1.1

Commits


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot rebase will rebase this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts

Merge request reports