Skip to content

Update dependency cookie-parser to ^1.4.7

2e053c3
Select commit
Loading
Failed to load commit list.
Open

Update dependency cookie-parser to ^1.4.7 #13

Update dependency cookie-parser to ^1.4.7
2e053c3
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 25, 2026 in 54m 44s

Security Report

You have successfully remediated 32 vulnerabilities, but introduced 5 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2025-7338

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/multer/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz None
CVE-2025-48997

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/multer/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.1 None
CVE-2025-47944

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/multer/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.0 None
CVE-2025-47935

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/multer/package.json

Dependency Hierarchy:

-> ❌ multer-1.4.5-lts.2.tgz (Vulnerable Library)

High 7.5 Direct multer-1.4.5-lts.2.tgz multer-1.4.5-lts.2.tgz 2.0.0 None
CVE-2024-47764

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/engine.io/node_modules/cookie/package.json

Dependency Hierarchy:

-> socket.io-3.1.2.tgz (Root Library)

   -> engine.io-4.1.2.tgz

     -> ❌ cookie-0.4.2.tgz (Vulnerable Library)

Medium 5.3 Transitive cookie-0.4.2.tgz socket.io-3.1.2.tgz Transitive 0.7.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-26996 minimatch-5.1.6.tgz
CVE-636288-474053 on-headers-1.0.2.tgz
CVE-2025-15284 qs-6.5.3.tgz
CVE-2024-45590 body-parser-1.20.2.tgz
CVE-2025-59343 tar-fs-2.1.1.tgz
CVE-2026-2391 qs-6.5.3.tgz
CVE-2024-47764 cookie-0.6.0.tgz
CVE-2024-4067 micromatch-4.0.7.tgz
CVE-2017-18214 moment-2.0.0.tgz
CVE-2026-26996 minimatch-9.0.5.tgz
CVE-2024-29415 ip-2.0.1.tgz
CVE-2024-43796 express-4.19.2.tgz
CVE-2025-64756 glob-10.4.5.tgz
CVE-2025-47944 multer-1.4.5-lts.1.tgz
CVE-2025-5889 brace-expansion-2.0.1.tgz
CVE-2025-15284 qs-6.11.0.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2025-7338 multer-1.4.5-lts.1.tgz
CVE-2025-5889 brace-expansion-1.1.11.tgz
CVE-2026-26996 minimatch-3.1.2.tgz
CVE-2024-47764 cookie-0.4.1.tgz
CVE-2025-69873 ajv-6.12.6.tgz
CVE-2022-25881 http-cache-semantics-3.8.1.tgz
CVE-2026-2391 qs-6.11.0.tgz
CVE-2025-13466 body-parser-1.20.2.tgz
CVE-2025-48997 multer-1.4.5-lts.1.tgz
CVE-2025-47935 multer-1.4.5-lts.1.tgz
CVE-2024-21538 cross-spawn-7.0.3.tgz
CVE-121740-819191 lodash-4.17.21.tgz
CVE-2025-7339 on-headers-1.0.2.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz
CVE-2024-43800 serve-static-1.15.0.tgz

Base branch total remaining vulnerabilities: 88
Base branch commit: null


Total libraries scanned: 978

Scan token: f8e55406e78543adaac29868d0418f60