> [!IMPORTANT] > CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE. > > DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY. `npm-fast-uri >= 3.0.0, < 3.1.3` CODE_REPOSITORY/commercelayer-react-components <ins>CVE-2026-13676</ins> **HIGH** remediate by: 2026-08-24T12:04:39.448Z - https://github.com/commercelayer/commercelayer-react-components/security/dependabot/234 > <details><summary>Related URLs</summary> > > - https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6 > - https://nvd.nist.gov/vuln/detail/CVE-2026-13676 > - https://github.com/fastify/fast-uri/pull/188 > - https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05 > - https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd > - https://github.com/fastify/fast-uri/commit/01db48010f594b98f7b323be18b393791c66ed1d > - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json > - https://github.com/fastify/fast-uri/releases/tag/v4.0.1 > - https://github.com/fastify/fast-uri/releases/tag/v3.1.3 > - https://github.com/fastify/fast-uri/releases/tag/v2.4.2 > - https://cna.openjsf.org/security-advisories.html > - https://bugzilla.redhat.com/show_bug.cgi?id=2494197 > - https://access.redhat.com/security/cve/CVE-2026-13676 > - https://access.redhat.com/errata/RHSA-2026:41929 > - https://access.redhat.com/errata/RHSA-2026:41928 > - https://access.redhat.com/errata/RHSA-2026:41066 > - https://access.redhat.com/errata/RHSA-2026:40945 > - https://access.redhat.com/errata/RHSA-2026:40262 > - https://access.redhat.com/errata/RHSA-2026:40118 > - https://access.redhat.com/errata/RHSA-2026:37628 > - https://access.redhat.com/errata/RHSA-2026:37585 > - https://access.redhat.com/errata/RHSA-2026:37186 > - https://access.redhat.com/errata/RHSA-2026:43038 > - https://access.redhat.com/errata/RHSA-2026:42815 > - https://access.redhat.com/errata/RHSA-2026:40765 > - https://access.redhat.com/errata/RHSA-2026:44239 > - https://access.redhat.com/errata/RHSA-2026:44268 > - https://access.redhat.com/errata/RHSA-2026:48126 > - https://access.redhat.com/errata/RHSA-2026:48124 > - https://access.redhat.com/errata/RHSA-2026:49642 > - https://access.redhat.com/errata/RHSA-2026:50479 > - https://access.redhat.com/errata/RHSA-2026:50340 > - https://access.redhat.com/errata/RHSA-2026:47728 > - https://access.redhat.com/errata/RHSA-2026:51196 > - https://access.redhat.com/errata/RHSA-2026:51197 > - https://access.redhat.com/errata/RHSA-2026:51342 > - https://access.redhat.com/errata/RHSA-2026:51348 > - https://access.redhat.com/errata/RHSA-2026:51349 > - https://github.com/advisories/GHSA-4c8g-83qw-93j6 > > </details> `npm-fast-uri >= 3.0.0, <= 3.1.3` CODE_REPOSITORY/commercelayer-react-components <ins>CVE-2026-16221</ins> **HIGH** remediate by: 2026-08-24T19:55:24.037Z - https://github.com/commercelayer/commercelayer-react-components/security/dependabot/236 > <details><summary>Related URLs</summary> > > - https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx > - https://nvd.nist.gov/vuln/detail/CVE-2026-16221 > - https://github.com/fastify/fast-uri/commit/0542a216860fd70c062a4730e620576f62ded057 > - https://github.com/fastify/fast-uri/commit/2d50fbabc80e4d0884fe0f6a98fe118ce6faa353 > - https://github.com/fastify/fast-uri/commit/9438266d6a7ded688c8bc7c4ba506da17f44a17b > - https://cna.openjsf.org/security-advisories.html > - https://github.com/fastify/fast-uri/releases/tag/v2.4.3 > - https://github.com/fastify/fast-uri/releases/tag/v3.1.4 > - https://github.com/fastify/fast-uri/releases/tag/v4.1.1 > - https://github.com/advisories/GHSA-v2hh-gcrm-f6hx > > </details> `npm-postcss <= 8.5.17` CODE_REPOSITORY/commercelayer-react-components <ins>GHSA-r28c-9q8g-f849</ins> **HIGH** remediate by: 2026-09-01T03:46:38.360Z - https://github.com/commercelayer/commercelayer-react-components/security/dependabot/253 > <details><summary>Related URLs</summary> > > - https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849 > - https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c > - https://github.com/postcss/postcss/releases/tag/8.5.18 > - https://github.com/advisories/GHSA-r28c-9q8g-f849 > > </details> `npm-fast-uri >= 3.0.0, < 3.1.5` CODE_REPOSITORY/commercelayer-react-components <ins>CVE-2026-18446</ins> **HIGH** remediate by: 2026-09-04T19:44:09.272Z - https://github.com/commercelayer/commercelayer-react-components/security/dependabot/257 > <details><summary>Related URLs</summary> > > - https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7 > - https://nvd.nist.gov/vuln/detail/CVE-2026-18446 > - https://github.com/fastify/fast-uri/commit/f3c6c905f47831007490f466c5945012e905cc52 > - https://cna.openjsf.org/security-advisories.html > - https://github.com/fastify/fast-uri/releases/tag/v4.1.2 > - https://github.com/advisories/GHSA-7p8r-x3mc-p8w7 > > </details> `npm-body-parser < 1.20.6` CODE_REPOSITORY/commercelayer-react-components <ins>CVE-2026-12590</ins> **LOW** remediate by: 2026-10-27T03:42:40.032Z - https://github.com/commercelayer/commercelayer-react-components/security/dependabot/248 > <details><summary>Related URLs</summary> > > - https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6 > - https://nvd.nist.gov/vuln/detail/CVE-2026-12590 > - https://github.com/expressjs/body-parser/pull/698 > - https://github.com/expressjs/body-parser/pull/741 > - https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d > - https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac > - https://cna.openjsf.org/security-advisories.html > - https://github.com/expressjs/body-parser/releases/tag/1.20.6 > - https://github.com/expressjs/body-parser/releases/tag/v2.3.0 > - https://github.com/advisories/GHSA-v422-hmwv-36x6 > > </details>
Important
CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.
DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.
npm-fast-uri >= 3.0.0, < 3.1.3CODE_REPOSITORY/commercelayer-react-components CVE-2026-13676 HIGH remediate by: 2026-08-24T12:04:39.448Znpm-fast-uri >= 3.0.0, <= 3.1.3CODE_REPOSITORY/commercelayer-react-components CVE-2026-16221 HIGH remediate by: 2026-08-24T19:55:24.037Znpm-postcss <= 8.5.17CODE_REPOSITORY/commercelayer-react-components GHSA-r28c-9q8g-f849 HIGH remediate by: 2026-09-01T03:46:38.360Znpm-fast-uri >= 3.0.0, < 3.1.5CODE_REPOSITORY/commercelayer-react-components CVE-2026-18446 HIGH remediate by: 2026-09-04T19:44:09.272Znpm-body-parser < 1.20.6CODE_REPOSITORY/commercelayer-react-components CVE-2026-12590 LOW remediate by: 2026-10-27T03:42:40.032Z