[security] active CVE triage (dependencies + deployment surface) - 2026-05-23 #10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Automated security triage found active unaddressed dependency CVEs affecting current
islandflowlockfile versions.Counters for this run:
unaddressed critical CVEs: 0unaddressed medium/low CVEs: 3unaddressed total CVEs: 9This pass reviewed Bun workspace manifests/locks plus deployment/runtime definitions (
oven/bun:1.3.11,clickhouse/clickhouse-server:23.8,redis:7.2,nats:2.10). The enumerated CVEs below are lockfile-confirmed. I reviewed the pinned image references, but image-level OS/package CVE expansion was not completed in this run because the local Docker daemon was unavailable.Findings
tarextraction paths.tar, relevant to local extraction workflows on macOS APFS.tar.<style>tags.websocket.close()can disclose uninitialized memory when passed a TypedArray reason.dirparameter.Project Impact
tarCVEs are pulled in through the Electron desktop toolchain (@electron-forge/cli,@electron-forge/core,@electron-forge/maker-zip) and primarily affect developer or packaging-time archive extraction rather than the live Bun services.wsaffects the runtime ingest services that use WebSocket connections (services/ingest-equities,services/ingest-news,services/ingest-options).postcssaffects the Next.js web build chain.tmpis transitive through the desktop packaging toolchain.Recommended Remediation
tarresolves to at least7.5.11andtmpresolves to at least0.2.4.wsto at least8.20.1.postcssresolves to at least8.5.10.Notes
References
bun audit[security] medium/high CVE triage (dependencies + deployment surface) - 2026-05-23to [security] active CVE triage (dependencies + deployment surface) - 2026-05-23genuinely shameful.
9 CVEs were running live for weeks to months, completely unnoticed. not that i checked... i was gonna get to it i swear lol (ig this is that) - git gud mf jesus
and this was just updating dependencies, the very start - the absolute lowest hanging fruit.
at least the whole server won't get pwn'd... again...
i hope.
fixed in
8464287c0clive on prod as of this AM