Skip to content

[GHSA-f27v-pv5m-c5g6] http-cache-semantics through 4.2.0 contains a cache... - #10195

Open
zsharpBDO wants to merge 1 commit into
zsharpBDO/advisory-improvement-10195from
zsharpBDO-GHSA-f27v-pv5m-c5g6
Open

zsharpBDO wants to merge 1 commit into
zsharpBDO/advisory-improvement-10195from
zsharpBDO-GHSA-f27v-pv5m-c5g6

Conversation

@zsharpBDO

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Summary

Comments
Fixed in this commit: kornelski/http-cache-semantics@9fb520b which was included in v4.3.0 of the package

New vector string was required - taken from the NIST link

Copilot AI balanced review requested due to automatic review settings October 6, 2026 21:12
@github-actions
github-actions Bot changed the base branch from main to zsharpBDO/advisory-improvement-10195 October 6, 2026 21:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The valid CVSS v3 score was removed and the modification timestamp predates the fix release.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates the advisory with package impact, remediation details, CVSS v4, and a summary.

Changes:

  • Marks npm versions through 4.2.0 as affected and 4.3.0 as fixed.
  • Adds a summary and updates CVSS v4 data.
File Description
GHSA-f27v-pv5m-c5g6.json Updates vulnerability metadata and affected versions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

"schema_version": "1.4.0",
"id": "GHSA-f27v-pv5m-c5g6",
"modified": "2026-09-18T18:31:44Z",
"modified": "2026-09-18T18:32:00Z",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This modified date was automatically generated by the GitHub Advisory form that created this PR. I'm open to making this change, but I think something in the form needs to be updated to ensure the modified date increases correctly.

Comment on lines 12 to +15
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was also an output of the form. That CVSS:3.1 does seem to line up with the NIST site though, so feel free to make that change. I don't have the permission

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants