Skip to content

Comments

Add CVE-2026-1615 to trivyignore (jsonpath - no fix available)#170

Merged
ssundahlTTD merged 4 commits intomainfrom
syw-UID2-6610-add-cve-2026-1615-trivyignore
Feb 19, 2026
Merged

Add CVE-2026-1615 to trivyignore (jsonpath - no fix available)#170
ssundahlTTD merged 4 commits intomainfrom
syw-UID2-6610-add-cve-2026-1615-trivyignore

Conversation

@sunnywu
Copy link
Contributor

@sunnywu sunnywu commented Feb 19, 2026

Summary

  • CVE-2026-1615 (HIGH): Arbitrary Code Execution in jsonpath 1.2.1 — no fix available; added to .trivyignore with 6-month expiry (2026-08-19)
  • CVE-2026-26996 (HIGH): ReDoS in minimatch (3.1.2, 5.1.6, 10.1.1) — fixed by adding "minimatch": "^10.2.1" to npm overrides in all 7 affected package.json files and regenerating package-lock.json files

Jira

UID2-6610

Test plan

  • Verify vulnerability scan passes after merge

🤖 Generated with Claude Code

sunnywu and others added 4 commits February 19, 2026 17:11
No patched version of jsonpath exists for CVE-2026-1615 (HIGH - Arbitrary Code
Execution). Adding to trivyignore with 6-month expiry. Tracked in UID2-6610.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
CVE-2026-26996 (HIGH): ReDoS via repeated wildcards in minimatch.
Added minimatch override to ^10.2.1 in all affected package.json files
and regenerated package-lock.json files. Tracked in UID2-6610.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
@ssundahlTTD ssundahlTTD merged commit 2ad35d1 into main Feb 19, 2026
2 checks passed
@ssundahlTTD ssundahlTTD deleted the syw-UID2-6610-add-cve-2026-1615-trivyignore branch February 19, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants