Skip to content

Fix decode-uri-component DoS in frontend - #148

Merged
gmunoz merged 1 commit into
masterfrom
fix-frontend-DoS
Sep 30, 2026
Merged

gmunoz merged 1 commit into
masterfrom
fix-frontend-DoS

Conversation

@gmunoz

@gmunoz gmunoz commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Upgrade query-string and use-query-params to consume the fixed decode-uri-component 0.5.0 through a supported ESM dependency chain. Migrate imports and React Router integration while preserving existing query-string serialization behavior.

This avoids forcing the ESM-only decoder into CommonJS query-string v7, which would leave an unsupported Node/tooling configuration.

This is a variant of #141.

Upgrade query-string and use-query-params to consume the fixed
decode-uri-component 0.5.0 through a supported ESM dependency chain.
Migrate imports and React Router integration while preserving existing
query-string serialization behavior.

This avoids forcing the ESM-only decoder into CommonJS query-string v7,
which would leave an unsupported Node/tooling configuration.
@gmunoz
gmunoz requested a review from mlim19 September 29, 2026 23:31
@gmunoz
gmunoz merged commit f1486f5 into master Sep 30, 2026
6 checks passed
artursarlo added a commit to pinterest/gprofiler-performance-studio that referenced this pull request Oct 1, 2026
…aml, transitive deps) (#114)

Backports frontend security fixes merged upstream (intel/gprofiler-performance-studio)
after our last CVE sync (origin #88, which covered up to intel#132):

- intel#148: fix decode-uri-component DoS. Upgrade query-string ^7 -> ^9.5.1 and
  use-query-params ^1.2.3 -> ^2.2.2 so the fixed decode-uri-component 0.5.0 is
  consumed through a supported ESM chain, and migrate imports / React Router
  integration (default queryString import + ReactRouter5Adapter). Pin
  decode-uri-component ^0.5.0 via resolutions.
- intel#137: add resolutions for browserslist ^4.28.7, nanoid ^3.3.18,
  @humanfs/node ^0.16.8 (decode-uri-component pin superseded by intel#148's 0.5.0).
- intel#139: js-yaml bumped to 4.3.2 via the existing ^4.3.0 resolution on
  lockfile regeneration.

yarn.lock regenerated locally with Node 20 / Yarn 1.22.22; 'yarn build' passes.
Divergent files (urls.js, ProfilesActions.jsx, AdhocProfilingView.jsx) had the
query-string migration applied manually; the rest match upstream. nginx/mTLS
divergence and the retained 'test' script are preserved as in #88.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants