Skip to content

Update dependency body-parser to v1.20.5 - autoclosed#351

Closed
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/body-parser-1.x-lockfile
Closed

Update dependency body-parser to v1.20.5 - autoclosed#351
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/body-parser-1.x-lockfile

Update dependency body-parser to v1.20.5

db71934
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Jun 22, 2026 in 12m 41s

Security Report

55 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-41907

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ uuid-11.1.0.tgz (Vulnerable Library)

Critical 9.8 Transitive uuid-11.1.0.tgz vivid-5.15.1.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 None
CVE-2026-41907

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> ❌ uuid-8.3.2.tgz (Vulnerable Library)

Critical 9.8 Transitive uuid-8.3.2.tgz vcr-sdk-1.3.0.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 None
CVE-2026-41907

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-2.22.0.tgz (Root Library)

   -> ❌ uuid-11.0.5.tgz (Vulnerable Library)

Critical 9.8 Transitive uuid-11.0.5.tgz opentok-2.22.0.tgz Transitive https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v12.0.1,https://github.com/uuidjs/uuid.git - v13.0.1 None
CVE-2026-44494

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 8.7 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.16.0 None
CVE-2026-44492

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 8.6 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.16.0,axios - 0.32.0 None
CVE-2026-4800

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-2.22.0.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 8.1 Transitive lodash-4.17.21.tgz opentok-2.22.0.tgz Transitive lodash-amd - 4.18.0,lodash - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0 None
CVE-2026-22029

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> react-router-dom-6.30.2.tgz (Root Library)

   -> ❌ router-1.23.1.tgz (Vulnerable Library)

High 8.0 Transitive router-1.23.1.tgz react-router-dom-6.30.2.tgz Transitive 1.23.2 None
CVE-2026-44496

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.5 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.16.0,axios - 0.32.0 None
CVE-2026-44488

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.5 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.16.0 None
CVE-2026-44487

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.5 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.16.0,axios - 0.32.0 None
CVE-2026-44486

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.5 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 0.32.0,axios - 1.16.0 None
CVE-2026-41675

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> video.js-8.23.7.tgz

     -> mpd-parser-1.3.1.tgz

       -> ❌ xmldom-0.8.11.tgz (Vulnerable Library)

High 7.5 Transitive xmldom-0.8.11.tgz vivid-5.15.1.tgz Transitive https://github.com/xmldom/xmldom.git - 0.8.13,https://github.com/xmldom/xmldom.git - 0.9.10 None
CVE-2026-41674

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> video.js-8.23.7.tgz

     -> mpd-parser-1.3.1.tgz

       -> ❌ xmldom-0.8.11.tgz (Vulnerable Library)

High 7.5 Transitive xmldom-0.8.11.tgz vivid-5.15.1.tgz Transitive https://github.com/xmldom/xmldom.git - 0.8.13,https://github.com/xmldom/xmldom.git - 0.9.10 None
CVE-2026-41673

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> video.js-8.23.7.tgz

     -> mpd-parser-1.3.1.tgz

       -> ❌ xmldom-0.8.11.tgz (Vulnerable Library)

High 7.5 Transitive xmldom-0.8.11.tgz vivid-5.15.1.tgz Transitive https://github.com/xmldom/xmldom.git - 0.8.13,https://github.com/xmldom/xmldom.git - 0.9.10 None
CVE-2026-41672

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> video.js-8.23.7.tgz

     -> mpd-parser-1.3.1.tgz

       -> ❌ xmldom-0.8.11.tgz (Vulnerable Library)

High 7.5 Transitive xmldom-0.8.11.tgz vivid-5.15.1.tgz Transitive https://github.com/xmldom/xmldom.git - 0.8.13,https://github.com/xmldom/xmldom.git - 0.9.10 None
CVE-2026-40181

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> react-router-dom-6.30.2.tgz (Root Library)

   -> ❌ react-router-6.30.2.tgz (Vulnerable Library)

High 7.5 Transitive react-router-6.30.2.tgz react-router-dom-6.30.2.tgz Transitive 6.30.4 None
CVE-2026-34601

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> video.js-8.23.7.tgz

     -> mpd-parser-1.3.1.tgz

       -> ❌ xmldom-0.8.11.tgz (Vulnerable Library)

High 7.5 Transitive xmldom-0.8.11.tgz vivid-5.15.1.tgz Transitive https://github.com/xmldom/xmldom.git - 0.9.9 None
CVE-2026-27904

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> glob-10.5.0.tgz

     -> ❌ minimatch-9.0.5.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.5.tgz vcr-sdk-1.3.0.tgz Transitive 9.0.7 None
CVE-2026-27903

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> glob-10.5.0.tgz

     -> ❌ minimatch-9.0.5.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.5.tgz vcr-sdk-1.3.0.tgz Transitive https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v4.2.5,https://github.com/isaacs/minimatch.git - v6.2.2,https://github.com/isaacs/minimatch.git - v10.2.3,https://github.com/isaacs/minimatch.git - v5.1.8,https://github.com/isaacs/minimatch.git - v9.0.7,https://github.com/isaacs/minimatch.git - v7.4.8,https://github.com/isaacs/minimatch.git - v8.0.6 None
CVE-2026-26996

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> glob-10.5.0.tgz

     -> ❌ minimatch-9.0.5.tgz (Vulnerable Library)

High 7.5 Transitive minimatch-9.0.5.tgz vcr-sdk-1.3.0.tgz Transitive https://github.com/isaacs/minimatch.git - v10.2.1,https://github.com/isaacs/minimatch.git - v5.1.7,https://github.com/isaacs/minimatch.git - v4.2.4,https://github.com/isaacs/minimatch.git - v3.1.3,https://github.com/isaacs/minimatch.git - v8.0.5,https://github.com/isaacs/minimatch.git - v9.0.6,https://github.com/isaacs/minimatch.git - v6.2.1,https://github.com/isaacs/minimatch.git - v7.4.7 None
CVE-2025-12758

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ validator-13.15.15.tgz (Vulnerable Library)

High 7.5 Direct validator-13.15.15.tgz validator-13.15.15.tgz 13.15.22 None
CVE-2026-42264

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.4 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.2 None
CVE-2026-42035

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.4 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42033

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.4 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42043

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.2 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2025-62718

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.2 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.0 None
CVE-2025-13465

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-2.22.0.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

High 7.2 Transitive lodash-4.17.21.tgz opentok-2.22.0.tgz Transitive lodash-amd - 4.17.23,lodash - 4.17.23,lodash-es - 4.17.23 None
CVE-2026-44495

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

High 7.0 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 1.15.2,axios - 0.31.1 None
CVE-2026-41238

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.9 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive 3.4.0 None
CVE-2026-42038

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 6.8 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-41239

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.8 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive 3.4.0 None
CVE-2026-42044

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 6.5 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.2 None
CVE-2026-41240

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.5 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive 3.4.0 None
CVE-2026-33750

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> glob-10.5.0.tgz

     -> minimatch-9.0.5.tgz

       -> ❌ brace-expansion-2.0.2.tgz (Vulnerable Library)

Medium 6.5 Transitive brace-expansion-2.0.2.tgz vcr-sdk-1.3.0.tgz Transitive https://github.com/juliangruber/brace-expansion.git - v2.0.3,https://github.com/juliangruber/brace-expansion.git - v3.0.2,https://github.com/juliangruber/brace-expansion.git - v5.0.5,https://github.com/juliangruber/brace-expansion.git - v1.1.13 None
CVE-2026-2950

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-2.22.0.tgz (Root Library)

   -> ❌ lodash-4.17.21.tgz (Vulnerable Library)

Medium 6.5 Transitive lodash-4.17.21.tgz opentok-2.22.0.tgz Transitive 4.17.23 None
CVE-2026-49978

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.1 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive https://github.com/cure53/DOMPurify.git - 3.4.7 None
CVE-2026-49459

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.1 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive https://github.com/cure53/DOMPurify.git - 3.4.6,dompurify - 3.4.6 None
CVE-2026-49458

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ dompurify-3.3.3.tgz (Vulnerable Library)

Medium 6.1 Transitive dompurify-3.3.3.tgz vivid-5.15.1.tgz Transitive https://github.com/cure53/DOMPurify.git - 3.4.6 None
CVE-2025-56200

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ validator-13.15.15.tgz (Vulnerable Library)

Medium 6.1 Direct validator-13.15.15.tgz validator-13.15.15.tgz validator - 13.15.20 None
CVE-2026-42042

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 5.4 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42039

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 5.3 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42037

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 5.3 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42036

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 5.3 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-42034

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 5.3 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-40895

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> axios-1.13.5.tgz (Root Library)

   -> ❌ follow-redirects-1.15.11.tgz (Vulnerable Library)

Medium 5.3 Transitive follow-redirects-1.15.11.tgz axios-1.13.5.tgz Transitive 1.16.0 None
CVE-2026-40895

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> video-client-network-test-5.0.0.tgz (Root Library)

   -> axios-1.13.5.tgz

     -> ❌ follow-redirects-1.15.11.tgz (Vulnerable Library)

Medium 5.3 Transitive follow-redirects-1.15.11.tgz video-client-network-test-5.0.0.tgz Transitive 1.16.0 None
CVE-2026-40895

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vcr-sdk-1.3.0.tgz (Root Library)

   -> axios-1.13.5.tgz

     -> ❌ follow-redirects-1.15.11.tgz (Vulnerable Library)

Medium 5.3 Transitive follow-redirects-1.15.11.tgz vcr-sdk-1.3.0.tgz Transitive 1.16.0 None
CVE-2026-40895

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-solutions-logging-1.1.5.tgz (Root Library)

   -> axios-1.13.5.tgz

     -> ❌ follow-redirects-1.15.11.tgz (Vulnerable Library)

Medium 5.3 Transitive follow-redirects-1.15.11.tgz opentok-solutions-logging-1.1.5.tgz Transitive 1.16.0 None
CVE-2026-44490

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 4.8 Direct axios-1.13.5.tgz axios-1.13.5.tgz axios - 0.32.0,axios - 1.16.0 None
CVE-2026-42041

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 4.8 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-40175

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Medium 4.8 Direct axios-1.13.5.tgz axios-1.13.5.tgz https://github.com/axios/axios.git - v1.15.0 None
CVE-2026-33532

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> css-11.13.5.tgz (Root Library)

   -> babel-plugin-11.13.5.tgz

     -> babel-plugin-macros-3.1.0.tgz

       -> cosmiconfig-7.1.0.tgz

         -> ❌ yaml-1.10.2.tgz (Vulnerable Library)

Medium 4.3 Transitive yaml-1.10.2.tgz css-11.13.5.tgz Transitive https://github.com/eemeli/yaml.git - v1.10.3,https://github.com/eemeli/yaml.git - v2.8.3 None
CVE-2026-42040

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> ❌ axios-1.13.5.tgz (Vulnerable Library)

Low 3.7 Direct axios-1.13.5.tgz axios-1.13.5.tgz 1.15.1 None
CVE-2026-41988

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> vivid-5.15.1.tgz (Root Library)

   -> ❌ uuid-11.1.0.tgz (Vulnerable Library)

Low 3.2 Transitive uuid-11.1.0.tgz vivid-5.15.1.tgz Transitive 11.1.1 None
CVE-2026-41988

Path to dependency file: /tutorials/vonage_video_react_app-feature-config/project/package.json

Path to vulnerable library: /tutorials/vonage_video_react_app-feature-config/project/package.json

Dependency Hierarchy:

-> opentok-2.22.0.tgz (Root Library)

   -> ❌ uuid-11.0.5.tgz (Vulnerable Library)

Low 3.2 Transitive uuid-11.0.5.tgz opentok-2.22.0.tgz Transitive 11.1.1 None

Base branch total remaining vulnerabilities: 29
Base branch commit: dfef31847e94e5c5348657ad64cfc12442623898


Total libraries scanned: 1427

Scan token: d7b9764a3aa34276a80eba29c3f92fa5