Skip to content

Update dependency body-parser to v1.20.4

3de77b0
Select commit
Loading
Failed to load commit list.
Open

Update dependency body-parser to v1.20.4 #38

Update dependency body-parser to v1.20.4
3de77b0
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed May 8, 2026 in 6m 9s

Security Report

You have successfully remediated 1 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-941441-362681

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> forever-2.0.0.tgz (Root Library)

   -> forever-monitor-2.0.0.tgz

     -> chokidar-2.1.8.tgz

       -> fsevents-1.2.9.tgz

         -> node-pre-gyp-0.12.0.tgz

           -> rimraf-2.6.3.tgz

             -> glob-7.1.3.tgz

               -> ❌ once-1.4.0.tgz (Vulnerable Library)

Critical 9.8 Transitive once-1.4.0.tgz forever-2.0.0.tgz #3
CVE-398484-724968

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> core-7.23.2.tgz (Root Library)

   -> traverse-7.29.0.tgz

     -> debug-4.4.3.tgz

       -> ❌ ms-2.1.3.tgz (Vulnerable Library)

Critical 9.8 Transitive ms-2.1.3.tgz core-7.23.2.tgz None
CVE-289561-266276

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> body-parser-1.20.4.tgz (Root Library)

   -> raw-body-2.5.3.tgz

     -> http-errors-2.0.1.tgz

       -> ❌ inherits-2.0.4.tgz (Vulnerable Library)

Critical 9.8 Transitive inherits-2.0.4.tgz body-parser-1.20.4.tgz None
CVE-214679-86261

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> forever-2.0.0.tgz (Root Library)

   -> forever-monitor-2.0.0.tgz

     -> chokidar-2.1.8.tgz

       -> fsevents-1.2.9.tgz

         -> node-pre-gyp-0.12.0.tgz

           -> nopt-4.0.1.tgz

             -> osenv-0.1.5.tgz

               -> ❌ os-tmpdir-1.0.2.tgz (Vulnerable Library)

Critical 9.8 Transitive os-tmpdir-1.0.2.tgz forever-2.0.0.tgz #3
CVE-2026-41239

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ dompurify-2.5.9.tgz (Vulnerable Library)

Medium 6.8 Direct dompurify-2.5.9.tgz dompurify-2.5.9.tgz Upgrade to version dompurify - 3.4.0 or greater None
CVE-2026-41240

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> ❌ dompurify-2.5.9.tgz (Vulnerable Library)

Medium 6.5 Direct dompurify-2.5.9.tgz dompurify-2.5.9.tgz Upgrade to version dompurify - 3.4.0 or greater None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-506311-612488 content-type-1.0.4.tgz

Base branch total remaining vulnerabilities: 80
Base branch commit: 716fe17b8d26ad794de274101da05107a712797c


Total libraries scanned: 446

Scan token: e4a921410ada48bca2c5f80f7d656e0d