Skip to content

[Snyk] Security upgrade @nestjs/platform-fastify from 9.3.9 to 11.1.11#341

Open
TheRedHatter wants to merge 1 commit into
snyk-fix-534ba1af199a066e09b142e5369a7f25from
snyk-fix-c840118c57a4e435702a4137c398ec40
Open

[Snyk] Security upgrade @nestjs/platform-fastify from 9.3.9 to 11.1.11#341
TheRedHatter wants to merge 1 commit into
snyk-fix-534ba1af199a066e09b142e5369a7f25from
snyk-fix-c840118c57a4e435702a4137c398ec40

Conversation

@TheRedHatter
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Interpretation Conflict
SNYK-JS-FASTIFYMIDDIE-16098213
  665  
critical severity Interpretation Conflict
SNYK-JS-FASTIFYMIDDIE-16098212
  655  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@TheRedHatter
Copy link
Copy Markdown
Owner Author

TheRedHatter commented Apr 17, 2026

Snyk checks have failed. 3 issues have been found so far.

Status Scan Engine Critical High Medium Low Total (3)
Open Source Security 0 3 0 0 3 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@TheRedHatter
Copy link
Copy Markdown
Owner Author

TheRedHatter commented Apr 17, 2026

Snyk checks have failed. 3 issues have been found so far.

Status Scan Engine Critical High Medium Low Total (3)
Open Source Security 0 3 0 0 3 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: MikroORM is vulnerable to SQL Injection via specially crafted object in npm @mikro-orm/core

CVE: GHSA-gwhv-j974-6fxm MikroORM is vulnerable to SQL Injection via specially crafted object (CRITICAL)

Affected versions: < 6.6.10; >= 7.0.0-dev.0 < 7.0.6

Patched version: 6.6.10

From: package-lock.jsonnpm/@mikro-orm/core@4.5.10

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@mikro-orm/core@4.5.10. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)

CVE: GHSA-vjh7-7g9h-fjfh Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) (CRITICAL)

Affected versions: < 6.6.1

Patched version: 6.6.1

From: package-lock.jsonnpm/jwk-to-pem@2.0.5npm/elliptic@6.5.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/elliptic@6.5.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm libxmljs vulnerable to type confusion when parsing specially crafted XML

CVE: GHSA-mg49-jqgw-gcj6 libxmljs vulnerable to type confusion when parsing specially crafted XML (CRITICAL)

Affected versions: <= 1.0.11

Patched version: No patched versions

From: package-lock.jsonnpm/libxmljs@1.0.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/libxmljs@1.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Cross-realm object access in Webpack 5

CVE: GHSA-hc6q-2mpp-qw7j Cross-realm object access in Webpack 5 (CRITICAL)

Affected versions: >= 5.0.0 < 5.76.0

Patched version: 5.76.0

From: client/package-lock.jsonnpm/@nestjs/cli@7.6.0npm/ts-loader@8.4.0npm/webpack@5.28.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.28.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm xmldom allows multiple root nodes in a DOM

CVE: GHSA-crh6-fp67-6883 xmldom allows multiple root nodes in a DOM (CRITICAL)

Affected versions: <= 0.6.0

Patched version: No patched versions

From: client/package-lock.jsonnpm/xmldom@0.6.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/xmldom@0.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copy link
Copy Markdown

@prisma-cloud-devsecops prisma-cloud-devsecops Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

Comment thread package.json
"@nestjs/graphql": "^12.2.0",
"@nestjs/mercurius": "^11.0.3",
"@nestjs/platform-fastify": "^9.3.9",
"@nestjs/platform-fastify": "^11.1.11",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nestjs/platform-fastify 11.1.11 / package.json

Total vulnerabilities: 9

Critical: 0 High: 3 Medium: 1 Low: 5
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2026-33806 HIGH HIGH - - Open
CVE-2026-2293 HIGH HIGH 9.8 11.1.14 Open
CVE-2026-33011 HIGH HIGH 7.5 11.1.16 Open
CVE-2025-69873 MEDIUM MEDIUM - - Open
CVE-2026-4926 LOW LOW - - Open
CVE-2026-4923 LOW LOW - - Open
CVE-2026-3635 LOW LOW - - Open
CVE-2026-25223 LOW LOW - - Open
CVE-2026-25224 LOW LOW - - Open

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants