Update dependency express to v4.21.1 (main) #66
Security Report
You have successfully remediated 12 vulnerabilities, but introduced 11 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2026-4867Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Not Defined | 0.017% | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.1.tgz | Transitive path-to-regexp - 0.1.13 |
None | ||
CVE-2024-52798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Not Defined | 0.302% | Transitive path-to-regexp-0.1.10.tgz |
express-4.21.1.tgz | Transitive 0.1.12 |
None | ||
CVE-2026-8723Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
5.3 | Not Defined | 0.044% | Transitive qs-6.13.0.tgz |
express-4.21.1.tgz | Transitive 6.15.2 |
None | ||
CVE-2026-8723Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
5.3 | Not Defined | 0.044% | Transitive qs-6.13.0.tgz |
body-parser-1.20.3.tgz | Transitive 6.15.2 |
None | ||
CVE-2026-8723Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> serverless-1.47.0.tgz (Root Library) -> json-refs-2.1.7.tgz -> path-loader-1.0.10.tgz -> superagent-3.8.3.tgz -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
5.3 | Not Defined | 0.044% | Transitive qs-6.13.0.tgz |
serverless-1.47.0.tgz | Transitive 6.15.2 |
#20 | ||
CVE-2026-2391Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.05% | Transitive qs-6.13.0.tgz |
express-4.21.1.tgz | Transitive 6.14.2 |
None | ||
CVE-2026-2391Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.05% | Transitive qs-6.13.0.tgz |
body-parser-1.20.3.tgz | Transitive 6.14.2 |
None | ||
CVE-2026-2391Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> serverless-1.47.0.tgz (Root Library) -> json-refs-2.1.7.tgz -> path-loader-1.0.10.tgz -> superagent-3.8.3.tgz -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.05% | Transitive qs-6.13.0.tgz |
serverless-1.47.0.tgz | Transitive 6.14.2 |
#20 | ||
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.21.1.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.04% | Transitive qs-6.13.0.tgz |
express-4.21.1.tgz | Transitive 6.14.1 |
None | ||
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.04% | Transitive qs-6.13.0.tgz |
body-parser-1.20.3.tgz | Transitive 6.14.1 |
None | ||
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> serverless-1.47.0.tgz (Root Library) -> json-refs-2.1.7.tgz -> path-loader-1.0.10.tgz -> superagent-3.8.3.tgz -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Not Defined | 0.04% | Transitive qs-6.13.0.tgz |
serverless-1.47.0.tgz | Transitive 6.14.1 |
#20 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2024-43799 | send-0.17.1.tgz |
| CVE-2024-45296 | path-to-regexp-0.1.7.tgz |
| CVE-2026-4867 | path-to-regexp-0.1.7.tgz |
| CVE-2024-47764 | cookie-0.4.0.tgz |
| CVE-2024-45590 | body-parser-1.19.0.tgz |
| CVE-2025-15284 | qs-6.7.0.tgz |
| CVE-2024-29041 | express-4.17.1.tgz |
| CVE-2024-43800 | serve-static-1.14.1.tgz |
| CVE-2026-2391 | qs-6.7.0.tgz |
| CVE-2024-43796 | express-4.17.1.tgz |
| CVE-2022-24999 | qs-6.7.0.tgz |
| CVE-2024-52798 | path-to-regexp-0.1.7.tgz |
Base branch total remaining vulnerabilities: 82
Base branch commit: aa914de618a178424105cc38c474133a60c17eeb
Total libraries scanned: 520
Scan token: b2b8efcd56c8495680117b5165ea30e3