Skip to content

Add Undici SOCKS5 fix references#8272

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8272from
cookesan:undici-hm92-fix-references
Open

Add Undici SOCKS5 fix references#8272
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8272from
cookesan:undici-hm92-fix-references

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit and v7 backport commit for nodejs/undici#5041 to GHSA-hm92-r4w5-c3mj.

Evidence checked:

  • PR [GHSA-7g45-4rm6-3mm3] Guava vulnerable to insecure use of temporary directory #5041 merged as commit a516f87098aad3c2daedfc24eada6f5a1594ed9e for the v8 line.
  • The v7.28.0 security release names backport commit 3805b8f8518882991044048c256e005dc3c10a85 for this advisory.
  • The v8.2.0 fixed tag contains the merge commit, and the v7.28.0 fixed tag contains the backport commit.
  • Both commits replace the single shared SOCKS5 pool with per-origin pools and add regression coverage for routing requests to distinct origins.
  • The npm undici 7.28.0 and 8.2.0 packages contain the fixed Socks5ProxyAgent implementation.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8272 June 29, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant