fix: upgrade express-rate-limit to 8.2.2, 8.1.1, 8.0.2 (CVE-2026-30827)#3440
Conversation
Automated dependency upgrade by Orbis Security AI
|
All contributors have signed the CLA. Thank you! ✅ |
There was a problem hiding this comment.
No issues found across 2 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: Dependency logic change (IP masking) and unrelated updates to optional binary dependencies (oh-my-opencode) prevent being 100% sure of no regressions.
|
I have read the CLA Document and I hereby sign the CLA |
|
[sisyphus-bot] PR sweep first-pass triage on
Needs rebase + review. Please rebase onto current Assigning |
|
@orbisai0security can you resolve merge conflicts? |
|
[sisyphus-bot] Hi orbisai0security. 🙏 Thanks for flagging CVE-2026-30827 in express-rate-limit; the IPv6 subnet-masking DoS is a real issue. Picking this back up from the 5/16 triage: I'm going to close this out so the rate-limit version doesn't get pinned backwards. If your scanner is still flagging the resolved version in |
|
Closing the loop here: the current dev branch now carries an express-rate-limit override at ^8.5.1, which is outside the CVE-2026-30827 affected range. Given that, this older PR is no longer needed. |
Summary
Upgrade express-rate-limit from 8.2.1 to 8.2.2, 8.1.1, 8.0.2 to fix CVE-2026-30827.
Vulnerability
CVE-2026-30827bun.lockDescription: express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking
Changes
bun.lockpackage.jsonVerification
Automated security fix by OrbisAI Security
Summary by cubic
Upgrades
express-rate-limitto 8.2.2 to fix CVE-2026-30827 (DoS for IPv4 due to incorrect IPv6 subnet masking). Updates lockfile to ensure safe resolution of related packages.express-rate-limitto 8.2.2.ip-addressto 10.1.0.oh-my-opencodebinaries to 3.17.2.Written for commit 73b6454. Summary will update on new commits.