Skip to content

Patch 0.x branch to resolve ReDos vulnerability #6689

Closed
@lnjbr

Description

Is your feature request related to a problem? Please describe.

The latest 0.x version of Axios should continue to receive updates for non-breaking security vulnerability resolutions. A ReDos vulnerability addressed in issue #6131 and resolved by PR #6132 could be applied to the 0.x branch.

More on the ReDos vulnerability: https://huntr.com/bounties/69a1aa07-c36e-4d9e-9325-b634e0aa4bb0

Describe the solution you'd like

The solution implemented by PR #6132 should be applied.

Describe alternatives you've considered

No response

Additional context/Screenshots

The following line would need to be updated:

https://github.com/axios/axios/blob/6acb5ef8ff127db65da85189b3ccaeb10b93121a/lib/helpers/combineURLs.js#L12

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions