Skip to content

build(deps): bump @trezor/connect-web from 9.7.1 to 9.7.2 in /frontend - #245

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/trezor/connect-web-9.7.2
Open

build(deps): bump @trezor/connect-web from 9.7.1 to 9.7.2 in /frontend#245
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/trezor/connect-web-9.7.2

build(deps): bump @trezor/connect-web from 9.7.1 to 9.7.2 in /frontend

a21cef2
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Apr 19, 2026 in 4s

53 new alerts including 3 critical severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 critical
  • 29 high
  • 18 medium
  • 3 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 3448 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: minimatch: Denial of Service via specially crafted glob patterns High

Package: minimatch
Installed Version: 3.1.2
Vulnerability CVE-2026-26996
Severity: HIGH
Fixed Version: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
Link: CVE-2026-26996

Check failure on line 14409 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

flatted: flatted: Unbounded recursion DoS in parse() revive phase High

Package: flatted
Installed Version: 3.3.3
Vulnerability CVE-2026-32141
Severity: HIGH
Fixed Version: 3.4.0
Link: CVE-2026-32141

Check failure on line 14409 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON. High

Package: flatted
Installed Version: 3.3.3
Vulnerability CVE-2026-33228
Severity: HIGH
Fixed Version: 3.4.2
Link: CVE-2026-33228

Check failure on line 14993 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

h3: h3: HTTP Request Smuggling due to improper case-sensitive parsing of Transfer-Encoding header High

Package: h3
Installed Version: 1.15.4
Vulnerability CVE-2026-23527
Severity: HIGH
Fixed Version: 1.15.5
Link: CVE-2026-23527

Check failure on line 14993 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields High

Package: h3
Installed Version: 1.15.4
Vulnerability CVE-2026-33128
Severity: HIGH
Fixed Version: 2.0.1-rc.15, 1.15.6
Link: CVE-2026-33128

Check failure on line 23503 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() High

Package: serialize-javascript
Installed Version: 4.0.0
Vulnerability GHSA-5c6j-r48x-rmvq
Severity: HIGH
Fixed Version: 7.0.3
Link: GHSA-5c6j-r48x-rmvq

Check failure on line 23464 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability High

Package: rollup
Installed Version: 2.79.2
Vulnerability CVE-2026-27606
Severity: HIGH
Fixed Version: 2.80.0, 3.30.0, 4.59.0
Link: CVE-2026-27606

Check failure on line 21204 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

svgo: SVGO: Denial of Service via XML entity expansion High

Package: svgo
Installed Version: 2.8.0
Vulnerability CVE-2026-29074
Severity: HIGH
Fixed Version: 2.8.1, 3.3.3, 4.0.1
Link: CVE-2026-29074

Check failure on line 18312 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation Critical

Package: jsonpath
Installed Version: 1.1.1
Vulnerability CVE-2026-1615
Severity: HIGH
Fixed Version: 1.3.0
Link: CVE-2026-1615

Check failure on line 19664 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters High

Package: path-to-regexp
Installed Version: 0.1.12
Vulnerability CVE-2026-4867
Severity: HIGH
Fixed Version: 0.1.13
Link: CVE-2026-4867

Check failure on line 18560 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

lodash: lodash: Arbitrary code execution via untrusted input in template imports High

Package: lodash
Installed Version: 4.17.21
Vulnerability CVE-2026-4800
Severity: HIGH
Fixed Version: 4.18.0
Link: CVE-2026-4800

Check failure on line 19057 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance High

Package: node-forge
Installed Version: 1.3.3
Vulnerability CVE-2026-33896
Severity: HIGH
Fixed Version: 1.4.0
Link: CVE-2026-33896

Check failure on line 18898 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: minimatch: Denial of Service via specially crafted glob patterns High

Package: minimatch
Installed Version: 9.0.3
Vulnerability CVE-2026-26996
Severity: HIGH
Fixed Version: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
Link: CVE-2026-26996

Check failure on line 18898 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns High

Package: minimatch
Installed Version: 9.0.3
Vulnerability CVE-2026-27903
Severity: HIGH
Fixed Version: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
Link: CVE-2026-27903

Check failure on line 18898 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions High

Package: minimatch
Installed Version: 9.0.3
Vulnerability CVE-2026-27904
Severity: HIGH
Fixed Version: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
Link: CVE-2026-27904

Check failure on line 19057 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() High

Package: node-forge
Installed Version: 1.3.3
Vulnerability CVE-2026-33891
Severity: HIGH
Fixed Version: 1.4.0
Link: CVE-2026-33891

Check failure on line 19057 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification High

Package: node-forge
Installed Version: 1.3.3
Vulnerability CVE-2026-33894
Severity: HIGH
Fixed Version: 1.4.0
Link: CVE-2026-33894

Check failure on line 19057 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures High

Package: node-forge
Installed Version: 1.3.3
Vulnerability CVE-2026-33895
Severity: HIGH
Fixed Version: 1.4.0
Link: CVE-2026-33895

Check failure on line 3448 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns High

Package: minimatch
Installed Version: 3.1.2
Vulnerability CVE-2026-27903
Severity: HIGH
Fixed Version: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
Link: CVE-2026-27903

Check failure on line 3448 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions High

Package: minimatch
Installed Version: 3.1.2
Vulnerability CVE-2026-27904
Severity: HIGH
Fixed Version: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
Link: CVE-2026-27904

Check failure on line 6052 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

nodejs-ws: denial of service when handling a request with many HTTP headers High

Package: ws
Installed Version: 8.16.0
Vulnerability CVE-2024-37890
Severity: HIGH
Fixed Version: 5.2.4, 6.2.3, 7.5.10, 8.17.1
Link: CVE-2024-37890

Check failure on line 25830 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions Medium

Package: underscore
Installed Version: 1.12.1
Vulnerability CVE-2026-27601
Severity: HIGH
Fixed Version: 1.13.8
Link: CVE-2026-27601

Check failure on line 24968 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

nodejs-nth-check: inefficient regular expression complexity High

Package: nth-check
Installed Version: 1.0.2
Vulnerability CVE-2021-3803
Severity: HIGH
Fixed Version: 2.0.1
Link: CVE-2021-3803

Check failure on line 9574 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig High

Package: axios
Installed Version: 1.13.2
Vulnerability CVE-2026-25639
Severity: HIGH
Fixed Version: 1.13.5, 0.30.3
Link: CVE-2026-25639

Check failure on line 9574 in frontend/package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization Medium

Package: axios
Installed Version: 1.13.2
Vulnerability CVE-2025-62718
Severity: MEDIUM
Fixed Version: 1.15.0, 0.31.0
Link: CVE-2025-62718