Files
calendar/apps/api
Sahitya ChandraandGitHub 2911168e4e fix(security): upgrade axios to 1.15.0 to fix critical CVEs (#28850)
Upgrades axios from 1.13.5 to 1.15.0 in apps/api/v2 and the root
resolutions field to resolve two critical vulnerabilities:

- GHSA-3p68-rc4w-qgx5: NO_PROXY hostname normalization bypass leading to SSRF
- GHSA-fvcv-3m26-pcqx: Unrestricted cloud metadata exfiltration via header injection

Both CVEs are fixed in axios >=1.15.0.
2026-04-12 15:15:42 -03:00
..
2026-01-02 12:47:00 +00:00
2025-12-29 19:41:41 -03:00