Skip to content

Update dependency jsdom to v26 - autoclosed - #100

Closed
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/jsdom-26.x
Closed

Update dependency jsdom to v26 - autoclosed#100
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/jsdom-26.x

Update dependency jsdom to v26

8c45bc2
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Jul 2, 2026 in 1m 48s

Security Report

You have successfully remediated 3 vulnerabilities, but introduced 8 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-41907

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> aws-sdk-2.1307.0.tgz (Root Library)

   -> ❌ uuid-8.0.0.tgz (Vulnerable Library)

Critical 9.8 Transitive uuid-8.0.0.tgz aws-sdk-2.1307.0.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 #⁠37
CVE-2026-33937

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

Critical 9.8 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33941

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.2 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-56876

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> puppeteer-18.2.1.tgz (Root Library)

   -> puppeteer-core-18.2.1.tgz

     -> ❌ extract-zip-2.0.1.tgz (Vulnerable Library)

High 8.1 Transitive extract-zip-2.0.1.tgz puppeteer-18.2.1.tgz #⁠75
CVE-2026-33940

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.1 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33938

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 8.1 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33939

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

High 7.5 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None
CVE-2026-33916

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nodemailer-express-handlebars-5.0.0.tgz (Root Library)

   -> express-handlebars-6.0.7.tgz

     -> ❌ handlebars-4.7.7.tgz (Vulnerable Library)

Medium 4.7 Transitive handlebars-4.7.7.tgz nodemailer-express-handlebars-5.0.0.tgz Transitive https://github.com/handlebars-lang/handlebars.js.git - v4.7.9 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-12143 form-data-4.0.0.tgz
CVE-2025-7783 form-data-4.0.0.tgz
CVE-2026-3449 once-2.0.0.tgz

Base branch total remaining vulnerabilities: 32
Base branch commit: null


Total libraries scanned: 156

Scan token: 5d1682c1f85e40368bd21e5f1585df47