aws / aws/aws-cdk

aws-cdk-lib: bundled @aws-cdk/asset-node-proxy-agent-v6@2.1.1 dependant package vulnerability CVE-2026-39983

Open
#37,566 4 comments 2 reactions 0 assignees View on GitHub
aws-cdk-lib bug effort/medium p1
Dominant language
TypeScript
Stars
12.9k
Forks
4.6k
Avg merge
2d 3h
Merged PRs (30d)
83

Description

### Describe the bug

`aws-cdk-lib@2.248.0` bundles `@aws-cdk/asset-node-proxy-agent-v6@2.1.1` which uses `basic-ftp@5.2.0`

Security scanning is flagging this against CVE-2026-39983. See https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q

I am not sure if the bundled proxy agent is susceptible to this issue. However basic-ftp@5.2.1 is listed as a patched version.

### Regression Issue

- [ ] Select this option if this issue appears to be a regression.

### Last Known Working CDK Library Version

_No response_

### Expected Behavior

n/a

### Current Behavior

n/a

### Reproduction Steps

Install aws-cdk-lib@2.248.0 & scan dependencies

### Possible Solution

_No response_

### Additional Information/Context

_No response_

### AWS CDK Library version (aws-cdk-lib)

2.248.0

### AWS CDK CLI version

2.1118.0

### Node.js Version

24

### OS

Linux

### Language

TypeScript

### Language Version

_No response_

### Other information

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by installing aws-cdk-lib@2.248.0 and scanning dependencies, then inspect how @aws-cdk/asset-node-proxy-agent-v6@2.1.1 bundles basic-ftp@5.2.0. Confirm whether the bundle is affected by CVE-2026-39983 and verify that the dependency is updated to patched basic-ftp@5.2.1.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.