Skip to content

Update dependency @vonage/server-sdk to v3

e95e272
Select commit
Loading
Failed to load commit list.
Open

Update dependency @vonage/server-sdk to v3 (main) #24

Update dependency @vonage/server-sdk to v3
e95e272
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Aug 4, 2025 in 44m 58s

Security Report

You have successfully remediated 10 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue Reachability
CVE-2024-43800

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/serve-static/package.json

Dependency Hierarchy:

-> express-4.17.1.tgz (Root Library)

   -> ❌ serve-static-1.14.1.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% serve-static-1.14.1.tgz Upgrade to version: serve-static - 1.16.0,2.1.0 #17

Reachable

CVE-2024-43799

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/send/package.json

Dependency Hierarchy:

-> express-4.17.1.tgz (Root Library)

   -> ❌ send-0.17.1.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% send-0.17.1.tgz Upgrade to version: send - 0.19.0 #17

Reachable

CVE-2024-43796

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/express/package.json

Dependency Hierarchy:

-> ❌ express-4.17.1.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% express-4.17.1.tgz Upgrade to version: express - 4.20.0,5.0.0 #17

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-7783 form-data-2.3.3.tgz
CVE-2020-15366 ajv-6.12.0.tgz
CVE-2021-3918 json-schema-0.2.3.tgz
CVE-2022-24999 qs-6.5.2.tgz
CVE-2022-23541 jsonwebtoken-8.5.1.tgz
CVE-2022-23540 jsonwebtoken-8.5.1.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2023-26136 tough-cookie-2.5.0.tgz
CVE-2022-23539 jsonwebtoken-8.5.1.tgz
CVE-2023-28155 request-2.88.2.tgz

Base branch total remaining vulnerabilities: 16
Base branch commit: null


Total libraries scanned: 123

Scan token: b3f4cdde8ea142ec9274e93253f4a9d0