How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Problem: ui5/cli@4.0.56 has a dependency on undici@6.26.0 which has a high vulnerability

calendar_today June 22, 2026 person kahori_f5 domain sap-bi-tools

Dear comminity: I generated a fiori element app( UI5 Version 1.136.16 ) on BAS and it has a high vulnerability which I cannot solve. undici Severity: high undici vulnerable to HTTP header injection via Set-Cookie percent-decoding - https://github.com/advisories/GHSA-p88m-4jfj-68fv undici WebSocket client vulnerable to denial of service via fragment count bypass - https://github.com/advisories/GHSA-vxpw-j846-p89q undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse - https://github.com/advisories/GHSA-35p6-xmwp-9g52 undici vulnerable to Set-Cookie SameSite attribute do

open_in_new Read original post