Skip to content

chore(deps): update dependency ajv to v8.18.0 [security]#3843

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate-npm-ajv-vulnerability
Open

chore(deps): update dependency ajv to v8.18.0 [security]#3843
renovate[bot] wants to merge 1 commit intomainfrom
renovate-npm-ajv-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 22, 2026

This PR contains the following updates:

Package Change Age Confidence
ajv (source) 8.12.08.18.0 age confidence

GitHub Vulnerability Alerts

CVE-2025-69873

ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation.


Release Notes

ajv-validator/ajv (ajv)

v8.18.0

Compare Source

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.17.1...v8.18.0

v8.17.1

Compare Source

What's Changed

Full Changelog: ajv-validator/ajv@v8.17.0...v8.17.1

Plus everything in 8.17.0 which failed to release

The only functional change is to switch from uri-js (which is no longer supported), to fast-uri. This is the second attempt and the team on fast-uri have been really helpful addressing the issues we found last time.

Revert "Revert fast-uri change (#​2444)" by @​gurgunday in #​2448
fix: ignore new eslint error for @​typescript-eslint/no-extraneous-class by @​jasoniangreen in #​2455
docs: clarify behaviour of addVocabulary by @​jasoniangreen in #​2454
docs: refactor to improve legibility by @​blottn in #​2432
Fix grammatical typo in managing-schemas.md by @​wetneb in #​2305
docs: Fix broken strict-mode link by @​alexanderjsx in #​2459
feat: add test for encoded refs and bump fast-uri by @​jasoniangreen in #​2449
fix: changes for @​typescript-eslint/array-type rule by @​jasoniangreen in #​2467
fixes #​2217 - clarify custom keyword naming by @​jasoniangreen in #​2457

v8.16.0

Compare Source

What's Changed

Full Changelog: ajv-validator/ajv@v8.15.0...v8.16.0

v8.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.14.0...v8.15.0

v8.14.0

Compare Source

What's Changed
New Contributors

Full Changelog: ajv-validator/ajv@v8.13.0...v8.14.0

v8.13.0

Compare Source

  • add named exports
  • update dependencies
  • update node.js

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency label Feb 22, 2026
@netlify
Copy link

netlify bot commented Feb 22, 2026

Deploy Preview for brilliant-pasca-3e80ec canceled.

Name Link
🔨 Latest commit 9459ae9
🔍 Latest deploy log https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/699afc8dba6f810008998ff7

@github-actions
Copy link

🚀 Performance Test Results

Test Configuration:

  • VUs: 4
  • Duration: 1m0s

Test Metrics:

  • Requests/s: 43.86
  • Iterations/s: 14.64
  • Failed Requests: 0.00% (0 of 2637)
📜 Logs

> performance@1.0.0 run-tests:testenv /home/runner/work/rafiki/rafiki/test/performance
> ./scripts/run-tests.sh -e test "-k" "-q" "--vus" "4" "--duration" "1m"

Cloud Nine GraphQL API is up: http://localhost:3101/graphql
Cloud Nine Wallet Address is up: http://localhost:3100/
Happy Life Bank Address is up: http://localhost:4100/
cloud-nine-wallet-test-backend already set
cloud-nine-wallet-test-auth already set
happy-life-bank-test-backend already set
happy-life-bank-test-auth already set
     data_received..................: 952 kB 16 kB/s
     data_sent......................: 2.0 MB 34 kB/s
     http_req_blocked...............: avg=7.16µs   min=2.11µs   med=5.15µs   max=2.61ms   p(90)=6.39µs   p(95)=6.91µs  
     http_req_connecting............: avg=329ns    min=0s       med=0s       max=387.31µs p(90)=0s       p(95)=0s      
     http_req_duration..............: avg=90.58ms  min=6.65ms   med=73.33ms  max=520.96ms p(90)=156.97ms p(95)=184.5ms 
       { expected_response:true }...: avg=90.58ms  min=6.65ms   med=73.33ms  max=520.96ms p(90)=156.97ms p(95)=184.5ms 
     http_req_failed................: 0.00%  ✓ 0         ✗ 2637
     http_req_receiving.............: avg=90.87µs  min=28.79µs  med=78.07µs  max=2.3ms    p(90)=118.91µs p(95)=156.18µs
     http_req_sending...............: avg=37.32µs  min=10.42µs  med=27.64µs  max=1.84ms   p(90)=41.91µs  p(95)=60µs    
     http_req_tls_handshaking.......: avg=0s       min=0s       med=0s       max=0s       p(90)=0s       p(95)=0s      
     http_req_waiting...............: avg=90.45ms  min=6.53ms   med=73.19ms  max=520.88ms p(90)=156.86ms p(95)=184.4ms 
     http_reqs......................: 2637   43.860853/s
     iteration_duration.............: avg=273.09ms min=184.32ms med=258.23ms max=1.03s    p(90)=340.51ms p(95)=367.58ms
     iterations.....................: 880    14.636917/s
     vus............................: 4      min=4       max=4 
     vus_max........................: 4      min=4       max=4 

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants