← All tasks
javascripteslint/eslint #20508Not a task: already works

Change Request: update ajv to 8.18.0

envgap__eslint__eslint-20508

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
61a24054411fa56ce74bef554846caa9d8cb01f5
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

eslint/eslint #20508 · read the original issue
### ESLint version

10.0.0

### What problem do you want to solve?

ESLint currently uses version `6.12.4` of `ajv`. The authors of `ajv` have released version `8.18.0` to mitigate [CVE-2025-69873](https://nvd.nist.gov/vuln/detail/CVE-2025-69873).

I realise the [ESLint Security Policy](https://github.com/eslint/eslint/security/policy) mentions:
> there are no security concerns related to regular expression performance

So, there is no reason to hurry upgrading `ajv`, but in the long run I would still recommend upgrading `ajv` because:
1. the version used in ESLint was released 5+ years ago
2. ESLint is 2 major versions behind on `ajv`, which is no longer updated
3. even though a Regex DoS is very unlikely in the case of ESLint, ESLint is still reported to be vulnerable by tools used in enterprise organizations to scan dependencies

### What do you think is the correct solution?

Update `ajv` to `8.18.0` or higher.

### Participation

- [ ] I am willing to submit a pull request for this change.

### Additional comments

_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]