Skip to content

[GHSA-jgm3-qmp2-c4p7] Vendure: Unauthenticated ReDoS via regex filter on SQLite backends - #9640

Open
checkmator wants to merge 1 commit into
checkmator/advisory-improvement-9640from
checkmator-GHSA-jgm3-qmp2-c4p7
Open

checkmator wants to merge 1 commit into
checkmator/advisory-improvement-9640from
checkmator-GHSA-jgm3-qmp2-c4p7

Conversation

@checkmator

Copy link
Copy Markdown

Updates

  • Affected products

Comments
Correct the npm package name from "vendure/core" to "@vendure/core".

The official package manifest at the affected v3.6.4 tag declares:
"name": "@vendure/core"
https://github.com/vendurehq/vendure/blob/v3.6.4/packages/core/package.json

The npm registry confirms that the patched 3.6.5 release is published under the same scoped package name:
https://registry.npmjs.org/@vendure%2fcore/3.6.5

The referenced fix also modifies packages/core and explicitly identifies this advisory:
vendurehq/vendure@f74cbbb

This corrects the affected package identity so consumers of the advisory can match it to the published npm dependency. No changes to the affected version range, patched version, severity, or vulnerability description are proposed.

@github

github commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

Hi there @michaelbromley! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions
github-actions Bot changed the base branch from main to checkmator/advisory-improvement-9640 September 20, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants