Skip to content

Update dependency express to v4.20.0

a46f2ef
Select commit
Loading
Failed to load commit list.
Open

Update dependency express to v4.20.0 #39

Update dependency express to v4.20.0
a46f2ef
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 20, 2026 in 1m 2s

Security Report

You have successfully remediated 11 vulnerabilities, but introduced 12 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-616547-419802

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ parseurl-1.3.3.tgz (Vulnerable Library)

Critical 9.8 Transitive parseurl-1.3.3.tgz express-4.20.0.tgz None
CVE-398484-724968

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> core-7.23.2.tgz (Root Library)

   -> traverse-7.29.0.tgz

     -> debug-4.4.3.tgz

       -> ❌ ms-2.1.3.tgz (Vulnerable Library)

Critical 9.8 Transitive ms-2.1.3.tgz core-7.23.2.tgz None
CVE-398484-724968

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> serve-static-1.16.0.tgz

     -> send-0.18.0.tgz

       -> ❌ ms-2.1.3.tgz (Vulnerable Library)

Critical 9.8 Transitive ms-2.1.3.tgz express-4.20.0.tgz None
CVE-289561-266276

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> http-errors-2.0.0.tgz

     -> ❌ inherits-2.0.4.tgz (Vulnerable Library)

Critical 9.8 Transitive inherits-2.0.4.tgz body-parser-1.20.3.tgz None
CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.20.0.tgz Transitive path-to-regexp - 0.1.12 None
CVE-2025-13466

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ body-parser-1.20.3.tgz (Vulnerable Library)

Medium 5.8 Direct body-parser-1.20.3.tgz body-parser-1.20.3.tgz body-parser - 2.2.1 None
CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ cookie-0.6.0.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.6.0.tgz express-4.20.0.tgz Transitive 0.7.0 None
CVE-2025-26791

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ dompurify-2.5.8.tgz (Vulnerable Library)

Medium 4.5 Direct dompurify-2.5.8.tgz dompurify-2.5.8.tgz 3.2.4 None
CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ qs-6.11.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.11.0.tgz express-4.20.0.tgz Transitive 6.14.2 None
CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive 6.14.2 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.20.0.tgz (Root Library)

   -> ❌ qs-6.11.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.11.0.tgz express-4.20.0.tgz Transitive qs - 6.14.1 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.3.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz body-parser-1.20.3.tgz Transitive qs - 6.14.1 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-15284 qs-6.5.2.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2026-2391 qs-6.5.2.tgz
CVE-2024-45590 body-parser-1.18.3.tgz
CVE-2022-24999 qs-6.5.2.tgz
CVE-2024-43800 serve-static-1.13.2.tgz
CVE-2025-13466 body-parser-1.18.3.tgz
CVE-275296-826791 qs-6.5.2.tgz
CVE-2024-10491 express-4.16.4.tgz
CVE-2024-43796 express-4.16.4.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 68
Base branch commit: 83155abda4658ac651ce8161120d08a2098f9f70


Total libraries scanned: 442

Scan token: fb0f0fa5ae9643cbb2188d4f063be5ef