Skip to content

Update dependency body-parser to v1.20.6 - #38

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/body-parser-1.x-lockfile
Open

Update dependency body-parser to v1.20.6#38
dev-mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/body-parser-1.x-lockfile

Update dependency body-parser to v1.20.6

4463c3b
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Sep 10, 2026 in 2m 18s

Security Report

You have successfully remediated 14 vulnerabilities, but introduced 8 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-666308-417910

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> qs-6.15.3.tgz

     -> side-channel-1.1.1.tgz

       -> side-channel-map-1.0.1.tgz

         -> get-intrinsic-1.3.0.tgz

           -> ❌ has-symbols-1.1.0.tgz (Vulnerable Library)

Critical 9.8 Transitive has-symbols-1.1.0.tgz express-4.22.2.tgz None
CVE-616547-419802

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> ❌ parseurl-1.3.3.tgz (Vulnerable Library)

Critical 9.8 Transitive parseurl-1.3.3.tgz express-4.22.2.tgz None
CVE-398484-724968

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> send-0.19.2.tgz

     -> ❌ ms-2.1.3.tgz (Vulnerable Library)

Critical 9.8 Transitive ms-2.1.3.tgz express-4.22.2.tgz None
CVE-289561-266276

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> http-errors-2.0.1.tgz

     -> ❌ inherits-2.0.4.tgz (Vulnerable Library)

Critical 9.8 Transitive inherits-2.0.4.tgz express-4.22.2.tgz None
CVE-2026-41239

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ dompurify-2.5.9.tgz (Vulnerable Library)

Medium 6.8 Direct dompurify-2.5.9.tgz dompurify-2.5.9.tgz 3.4.0 None
CVE-2026-41240

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ dompurify-2.5.9.tgz (Vulnerable Library)

Medium 6.5 Direct dompurify-2.5.9.tgz dompurify-2.5.9.tgz 3.4.0 None
CVE-2026-82417

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> ❌ qs-6.15.3.tgz (Vulnerable Library)

Medium 5.3 Transitive qs-6.15.3.tgz express-4.22.2.tgz Transitive qs - 6.16.0 None
CVE-2026-82562

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.22.2.tgz (Root Library)

   -> ❌ qs-6.15.3.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.15.3.tgz express-4.22.2.tgz Transitive qs - 6.16.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-15284 qs-6.5.2.tgz
CVE-506311-612488 content-type-1.0.4.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2026-4867 path-to-regexp-0.1.7.tgz
CVE-2024-45590 body-parser-1.18.3.tgz
CVE-2022-24999 qs-6.5.2.tgz
CVE-2024-43800 serve-static-1.13.2.tgz
CVE-2026-12590 body-parser-1.18.3.tgz
CVE-2025-13466 body-parser-1.18.3.tgz
CVE-275296-826791 qs-6.5.2.tgz
CVE-2024-10491 express-4.16.4.tgz
CVE-2026-82417 qs-6.5.2.tgz
CVE-2024-43796 express-4.16.4.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 95
Base branch commit: 716fe17b8d26ad794de274101da05107a712797c


Total libraries scanned: 439

Scan token: b6b8bfb7a52e40cf8edee6a9ce1ca85f