Skip to content

Upgrading sha.js for CVE-2025-9288 throws an error #8147

@sihua-caoliu-veriforce

Description

@sihua-caoliu-veriforce

We are currently working to address a CVE-2025-9288 vulnerability found in the sha.js dependency associated with @apollo/utils.createhash. As part of our efforts, we attempted to override the library version to "sha.js": "2.4.12" in order to mitigate this security risk. Unfortunately, this upgrade has resulted in a ServerParseError thrown in the frontend. We would greatly appreciate any guidance or suggestions on how to proceed to resolve this issue effectively

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions