Skip to content

[pull] main from calcom:main#709

Merged
pull[bot] merged 1 commit intocode:mainfrom
calcom:main
Apr 12, 2026
Merged

[pull] main from calcom:main#709
pull[bot] merged 1 commit intocode:mainfrom
calcom:main

Conversation

@pull
Copy link
Copy Markdown

@pull pull Bot commented Apr 12, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Upgrades axios from 1.13.5 to 1.15.0 in apps/api/v2 and the root
resolutions field to resolve two critical vulnerabilities:

- GHSA-3p68-rc4w-qgx5: NO_PROXY hostname normalization bypass leading to SSRF
- GHSA-fvcv-3m26-pcqx: Unrestricted cloud metadata exfiltration via header injection

Both CVEs are fixed in axios >=1.15.0.
@pull pull Bot locked and limited conversation to collaborators Apr 12, 2026
@pull pull Bot added the ⤵️ pull label Apr 12, 2026
@pull pull Bot merged commit 2911168 into code:main Apr 12, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant