Update dependency body-parser to ~1.20.6 - #33
Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
Open
Update dependency body-parser to ~1.20.6#33dev-mend-for-github-com[bot] wants to merge 1 commit into
dev-mend-for-github-com[bot] wants to merge 1 commit into
Dev - Mend for GitHub.com / Mend Security Check
failed
Jul 26, 2026 in 3m 2s
Security Report
You have successfully remediated 9 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-666308-417910Path to dependency file: /package.json Path to vulnerable library: /node_modules/has-symbols/package.json Dependency Hierarchy: -> body-parser-1.20.6.tgz (Root Library) -> qs-6.15.3.tgz -> side-channel-1.1.1.tgz -> side-channel-map-1.0.1.tgz -> get-intrinsic-1.3.0.tgz -> ❌ has-symbols-1.1.0.tgz (Vulnerable Library) |
9.8 | Transitive has-symbols-1.1.0.tgz |
body-parser-1.20.6.tgz | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2024-45590 | body-parser-1.13.3.tgz |
| CVE-30766-190127 | body-parser-1.13.3.tgz |
| CVE-2017-16137 | debug-2.2.0.tgz |
| CVE-2026-12590 | body-parser-1.13.3.tgz |
| CVE-2017-16119 | fresh-0.3.0.tgz |
| CVE-2017-16082 | pg-5.1.0.tgz |
| CVE-978073-645225 | bytes-2.1.0.tgz |
| CVE-784887-623763 | statuses-1.5.0.tgz |
| CVE-2025-13466 | body-parser-1.13.3.tgz |
Base branch total remaining vulnerabilities: 64
Base branch commit: null
Total libraries scanned: 118
Scan token: e34e4d5dc896436aa21d5f0d8fe7490d
Loading