Skip to content

Update dependency express to v4.20.0

d9b8a53
Select commit
Loading
Failed to load commit list.
Open

Update dependency express to v4.20.0 #22

Update dependency express to v4.20.0
d9b8a53
Select commit
Loading
Failed to load commit list.
Staging - WhiteSource for GitHub.com / Mend Security Check failed Apr 8, 2026 in 7m 24s

Security Report

You have successfully remediated 9 vulnerabilities, but introduced 7 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-4867

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.20.0.tgz None

Reachable

CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.20.0.tgz Transitive path-to-regexp - 0.1.12 None

Reachable

CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz express-4.20.0.tgz Transitive cookie - 0.7.0 None

Reachable

CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ qs-6.11.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.11.0.tgz express-4.20.0.tgz Transitive 6.14.2 None

Reachable

CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive 6.14.2 None

Reachable

CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ qs-6.11.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.11.0.tgz express-4.20.0.tgz None

Reachable

CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-15284 qs-6.5.2.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2026-2391 qs-6.5.2.tgz
CVE-2026-4867 path-to-regexp-0.1.7.tgz
CVE-2024-45590 body-parser-1.18.3.tgz
CVE-2022-24999 qs-6.5.2.tgz
CVE-2024-43800 serve-static-1.13.2.tgz
CVE-2024-43796 express-4.16.4.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 66
Base branch commit: 87cb511a22269d0fea8ca4c1fcebbf6720e00921


Total libraries scanned: 403

Scan token: c631d9502c52424eb8edcacf02783282