Skip to content

Update dependency express to v4.22.0

0cfbd29
Select commit
Loading
Failed to load commit list.
Open

Update dependency express to v4.22.0 #2

Update dependency express to v4.22.0
0cfbd29
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed May 22, 2026 in 18m 6s

Security Report

8 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-3520

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.1.1 #⁠28

Reachable

CVE-2026-3304

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.1.0 #⁠28

Reachable

CVE-2026-2359

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.1.0 #⁠28

Reachable

CVE-2025-7338

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.2 #⁠28

Reachable

CVE-2025-48997

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.1 #⁠28

Reachable

CVE-2025-47944

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.0 #⁠28

Reachable

CVE-2025-47935

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.0 #⁠28

Reachable

CVE-2026-8723

Path to dependency file: /backend/package.json

Path to vulnerable library: /backend/package.json

Dependency Hierarchy:

-> express-4.22.0.tgz (Root Library)

   -> ❌ qs-6.14.2.tgz (Vulnerable Library)

Medium 5.3 Transitive qs-6.14.2.tgz express-4.22.0.tgz Transitive 6.15.2 None

Unreachable

Base branch total remaining vulnerabilities: 191
Base branch commit: a3ba1679b8965c9f00f5ca1f92a5800372757c57


Total libraries scanned: 2154

Scan token: a1410d27fff845fea151e573b9a3c8db