π Security Alerts β IBM/networking-java-sdk
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @sridhargk @MalarvizhiK @kennburger @jkalandaibm @pinky-bhargava @gahlaut-rahul @arjunchauhanibm @DevxNetworkServices
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Fix PR |
| π΄ critical |
CVE-2026-33937 |
handlebars |
>= 4.0.0, <= 4.7.8 |
4.7.9 |
β |
| π high |
CVE-2026-26960 |
tar |
< 7.5.8 |
7.5.8 |
β |
| π high |
CVE-2026-27903 |
minimatch |
>= 10.0.0, < 10.2.3 |
10.2.3 |
β |
| π high |
CVE-2026-29786 |
tar |
<= 7.5.9 |
7.5.10 |
β |
| π high |
CVE-2026-31802 |
tar |
<= 7.5.10 |
7.5.11 |
β |
| π high |
CVE-2026-1528 |
undici |
>= 7.0.0, < 7.24.0 |
7.24.0 |
β |
| π high |
CVE-2026-33938 |
handlebars |
>= 4.0.0, <= 4.7.8 |
4.7.9 |
β |
| π high |
CVE-2026-33940 |
handlebars |
>= 4.0.0, <= 4.7.8 |
4.7.9 |
β |
| π high |
CVE-2026-33941 |
handlebars |
>= 4.0.0, <= 4.7.8 |
4.7.9 |
β |
| π high |
CVE-2026-4800 |
lodash-es |
>= 4.0.0, <= 4.17.23 |
4.18.0 |
β |
| π high |
CVE-2026-48815 |
sigstore |
<= 4.1.0 |
4.1.1 |
β |
| π high |
CVE-2026-59869 |
js-yaml |
>= 4.0.0, < 4.3.0 |
4.3.0 |
β |
| π high |
CVE-2026-13697 |
undici |
>= 7.0.0, < 7.29.0 |
7.29.0 |
β |
| π high |
CVE-2026-69192 |
ip-address |
<= 10.3.0 |
10.3.1 |
β |
| π high |
GHSA-5p4m-2wfm-xmqj |
js-yaml |
>= 4.0.0, < 4.3.1 |
4.3.1 |
β |
| π‘ medium |
CVE-2026-1525 |
undici |
>= 7.0.0, < 7.24.0 |
7.24.0 |
β |
| π‘ medium |
CVE-2026-1527 |
undici |
>= 7.0.0, < 7.24.0 |
7.24.0 |
β |
| π‘ medium |
CVE-2026-33672 |
picomatch |
< 2.3.2 |
2.3.2 |
β |
| π‘ medium |
GHSA-7rx3-28cr-v5wh |
handlebars |
>= 4.6.0, <= 4.7.8 |
4.7.9 |
β |
| π‘ medium |
CVE-2026-2950 |
lodash-es |
<= 4.17.23 |
4.18.0 |
β |
| π‘ medium |
CVE-2026-33916 |
handlebars |
>= 4.0.0, < 4.7.9 |
4.7.9 |
β |
| π‘ medium |
CVE-2026-42338 |
ip-address |
<= 10.1.0 |
10.1.1 |
β |
| π‘ medium |
CVE-2026-9678 |
undici |
>= 7.0.0, < 7.28.0 |
7.28.0 |
β |
| π‘ medium |
CVE-2026-9679 |
undici |
>= 7.0.0, < 7.28.0 |
7.28.0 |
β |
| π‘ medium |
CVE-2026-53655 |
tar |
<= 7.5.15 |
7.5.16 |
β |
| π‘ medium |
CVE-2026-48758 |
@sigstore/core |
<= 3.2.0 |
3.2.1 |
β |
| π‘ medium |
CVE-2026-48816 |
@sigstore/verify |
= 3.1.0 |
3.1.1 |
β |
| π‘ medium |
CVE-2026-53550 |
js-yaml |
>= 4.0.0, <= 4.1.1 |
4.2.0 |
β |
| π‘ medium |
CVE-2026-59871 |
tar |
<= 7.5.17 |
7.5.18 |
β |
| π‘ medium |
CVE-2026-16728 |
undici |
>= 7.0.0, < 7.29.0 |
7.29.0 |
β |
| π‘ medium |
CVE-2026-14643 |
undici |
>= 7.0.0, < 7.29.0 |
7.29.0 |
β |
| π‘ medium |
CVE-2026-16729 |
undici |
>= 7.0.0, < 7.29.0 |
7.29.0 |
β |
| π‘ medium |
CVE-2026-15157 |
undici |
>= 7.0.0, < 7.29.0 |
7.29.0 |
β |
| π΅ low |
GHSA-442j-39wm-28r2 |
handlebars |
>= 4.0.0, <= 4.7.8 |
4.7.9 |
β |
| π΅ low |
CVE-2026-6733 |
undici |
>= 7.0.0, < 7.28.0 |
7.28.0 |
β |
| π΅ low |
CVE-2026-11525 |
undici |
>= 7.0.0, < 7.28.0 |
7.28.0 |
β |
| π΅ low |
CVE-2026-9358 |
postcss-selector-parser |
>= 7.1.0, < 7.1.3 |
7.1.3 |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π Security Alerts β IBM/networking-java-sdk
Attention: @sridhargk @MalarvizhiK @kennburger @jkalandaibm @pinky-bhargava @gahlaut-rahul @arjunchauhanibm @DevxNetworkServices
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.