Update dependency body-parser to v1.20.4 (main) #14
Mend for GitHub.com / WhiteSource Security Check
failed
May 29, 2026 in 1m 21s
Security Report
You have successfully remediated 17 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|---|
CVE-2026-8723Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.4.tgz (Root Library) -> ❌ qs-6.14.2.tgz (Vulnerable Library) |
5.3 | Not Defined | 0.044% | Transitive qs-6.14.2.tgz |
body-parser-1.20.4.tgz | Transitive 6.15.2 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-7783 | form-data-2.3.3.tgz |
| CVE-2024-45590 | body-parser-1.18.3.tgz |
| CVE-2025-15284 | qs-6.5.2.tgz |
| CVE-2021-3918 | json-schema-0.2.3.tgz |
| CVE-2025-69873 | ajv-6.12.2.tgz |
| CVE-2020-15366 | ajv-6.12.2.tgz |
| CVE-2022-24999 | qs-6.5.2.tgz |
| CVE-2026-41907 | uuid-2.0.3.tgz |
| CVE-2022-23541 | jsonwebtoken-8.5.1.tgz |
| CVE-2022-25883 | semver-5.7.1.tgz |
| CVE-2022-23540 | jsonwebtoken-8.5.1.tgz |
| CVE-2025-65945 | jws-3.2.2.tgz |
| CVE-2022-23539 | jsonwebtoken-8.5.1.tgz |
| CVE-2026-41907 | uuid-3.4.0.tgz |
| CVE-2023-26136 | tough-cookie-2.5.0.tgz |
| CVE-2023-28155 | request-2.88.2.tgz |
| CVE-2026-2391 | qs-6.5.2.tgz |
Base branch total remaining vulnerabilities: 31
Base branch commit: f1591f9e7e403e0cb110a7c12eea1553838dca6d
Total libraries scanned: 88
Scan token: e02d160c894f438090550d3eef3fd907
Loading