Skip to content

Update dependency express to v4.21.1

183b46c
Select commit
Loading
Failed to load commit list.
Open

Update dependency express to v4.21.1 (main) #66

Update dependency express to v4.21.1
183b46c
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed May 29, 2026 in 2m 1s

Security Report

You have successfully remediated 12 vulnerabilities, but introduced 11 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-4867

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Not Defined 0.017% Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive path-to-regexp - 0.1.13 None

Reachable

CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Not Defined 0.302% Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive 0.1.12 None

Reachable

CVE-2026-8723

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Medium 5.3 Not Defined 0.044% Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.15.2 None

Reachable

CVE-2026-8723

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Medium 5.3 Not Defined 0.044% Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive 6.15.2 None

Reachable

CVE-2026-8723

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> serverless-1.47.0.tgz (Root Library)

   -> json-refs-2.1.7.tgz

     -> path-loader-1.0.10.tgz

       -> superagent-3.8.3.tgz

         -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Medium 5.3 Not Defined 0.044% Transitive qs-6.13.0.tgz serverless-1.47.0.tgz Transitive 6.15.2 #⁠20

Reachable

CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.05% Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.14.2 None

Reachable

CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.05% Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive 6.14.2 None

Reachable

CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> serverless-1.47.0.tgz (Root Library)

   -> json-refs-2.1.7.tgz

     -> path-loader-1.0.10.tgz

       -> superagent-3.8.3.tgz

         -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.05% Transitive qs-6.13.0.tgz serverless-1.47.0.tgz Transitive 6.14.2 #⁠20

Reachable

CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.04% Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.14.1 None

Reachable

CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.04% Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive 6.14.1 None

Reachable

CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> serverless-1.47.0.tgz (Root Library)

   -> json-refs-2.1.7.tgz

     -> path-loader-1.0.10.tgz

       -> superagent-3.8.3.tgz

         -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Not Defined 0.04% Transitive qs-6.13.0.tgz serverless-1.47.0.tgz Transitive 6.14.1 #⁠20

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2024-43799 send-0.17.1.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2026-4867 path-to-regexp-0.1.7.tgz
CVE-2024-47764 cookie-0.4.0.tgz
CVE-2024-45590 body-parser-1.19.0.tgz
CVE-2025-15284 qs-6.7.0.tgz
CVE-2024-29041 express-4.17.1.tgz
CVE-2024-43800 serve-static-1.14.1.tgz
CVE-2026-2391 qs-6.7.0.tgz
CVE-2024-43796 express-4.17.1.tgz
CVE-2022-24999 qs-6.7.0.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 82
Base branch commit: aa914de618a178424105cc38c474133a60c17eeb


Total libraries scanned: 520

Scan token: b2b8efcd56c8495680117b5165ea30e3