Skip to content

[7.115.x] Fix CVE-2025-69873 by updating ajv to patched versions#339

Merged
rgrunber merged 3 commits intoeclipse-che:7.115.xfrom
sbouchet:CVE-2025-69873
Mar 10, 2026
Merged

[7.115.x] Fix CVE-2025-69873 by updating ajv to patched versions#339
rgrunber merged 3 commits intoeclipse-che:7.115.xfrom
sbouchet:CVE-2025-69873

Conversation

@sbouchet
Copy link
Contributor

@sbouchet sbouchet commented Mar 3, 2026

This PR fixes GHSA-2g4f-4pwh-qvx6: ReDoS via $data reference

ajv version is updated to 6.14.0

fixes https://issues.redhat.com/browse/CRW-10192

Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
@sbouchet sbouchet changed the title update Fix CVE-2025-69873 by updating ajv to patched versions Fix CVE-2025-69873 by updating ajv to patched versions Mar 3, 2026
Signed-off-by: Stephane Bouchet <sbouchet@redhat.com>
@sbouchet sbouchet changed the title Fix CVE-2025-69873 by updating ajv to patched versions [7.115.x] Fix CVE-2025-69873 by updating ajv to patched versions Mar 4, 2026
@rgrunber rgrunber self-requested a review March 5, 2026 04:16
@rgrunber rgrunber merged commit 3ab77c9 into eclipse-che:7.115.x Mar 10, 2026
9 checks passed
@sbouchet sbouchet deleted the CVE-2025-69873 branch March 10, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants