Skip to content

Update dependency express to v4.21.1

a40bfc0
Select commit
Loading
Failed to load commit list.
Open

Update dependency express to v4.21.1 #17

Update dependency express to v4.21.1
a40bfc0
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed May 29, 2026 in 5m 9s

Security Report

You have successfully remediated 6 vulnerabilities, but introduced 5 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-4867

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive path-to-regexp - 0.1.13 None
CVE-2024-52798

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library)

High 7.5 Transitive path-to-regexp-0.1.10.tgz express-4.21.1.tgz Transitive 0.1.12 None
CVE-2026-8723

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Medium 5.3 Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.15.2 None
CVE-2026-2391

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.14.2 None
CVE-2025-15284

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.21.1.tgz (Root Library)

   -> ❌ qs-6.13.0.tgz (Vulnerable Library)

Low 3.7 Transitive qs-6.13.0.tgz express-4.21.1.tgz Transitive 6.14.1 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-4867 path-to-regexp-0.1.7.tgz
CVE-2024-43796 express-4.17.1.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2024-47764 cookie-0.4.0.tgz
CVE-2024-29041 express-4.17.1.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 191
Base branch commit: null


Total libraries scanned: 1652

Scan token: 01204e1faa6c4fbaa2b85f1820851d6e