Skip to content

Vulnerabilities as of 2026-09-18 #206

Description

@github-actions

Total 1 package affected by 2 known vulnerabilities (0 Critical, 0 High, 2 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
2 vulnerabilities can be fixed.

OSV URL CVSS Ecosystem Package Version Fixed Version Source
https://osv.dev/GHSA-4mjr-xmp4-gh2g 6.3 npm qs 6.15.3 6.16.0 package-lock.json
https://osv.dev/GHSA-x5fp-wj9c-mxmx 6.3 npm qs 6.15.3 6.16.0 package-lock.json

npm audit

Severity Name Version Fix Available
moderate body-parser 1.20.5 - 1.20.6 true
moderate express 4.22.2 true
moderate qs 2.2.5 - 6.15.3 true
npm list
  • @bedrock/express@8.8.0
    • body-parser@1.20.6
      • qs@6.15.3
    • express@4.22.2
      • body-parser@1.20.6
      • qs@6.15.3
  • @bedrock/server@5.2.0
    • express@4.22.2

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    OSVVulnerabilities found by https://osv.dev/

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions