π Security Alerts β IBM/libras
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: (no direct admin collaborators assigned to this repo β please add an admin to receive security notifications)
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Fix PR |
| π΄ critical |
CVE-2021-44906 |
minimist |
>= 1.0.0, < 1.2.6 |
1.2.6 |
β |
| π‘ medium |
CVE-2023-28155 |
request |
<= 2.88.2 |
β |
β |
| π high |
CVE-2020-8116 |
dot-prop |
< 4.2.1 |
4.2.1 |
β |
| π‘ medium |
CVE-2021-32640 |
ws |
>= 6.0.0, < 6.2.2 |
6.2.2 |
β |
| π‘ medium |
CVE-2021-29060 |
color-string |
< 1.5.5 |
1.5.5 |
β |
| π‘ medium |
GHSA-xx4c-jj58-r7x6 |
validator |
>= 11.1.0, < 13.7.0 |
13.7.0 |
β |
| π΄ critical |
CVE-2021-3918 |
json-schema |
< 0.4.0 |
0.4.0 |
β |
| π high |
CVE-2021-3807 |
ansi-regex |
>= 5.0.0, < 5.0.1 |
5.0.1 |
β |
| π high |
CVE-2021-3749 |
axios |
< 0.21.2 |
0.21.2 |
β |
| π high |
CVE-2022-24999 |
qs |
>= 6.5.0, < 6.5.3 |
6.5.3 |
PR |
| π‘ medium |
CVE-2023-26136 |
tough-cookie |
< 4.1.3 |
4.1.3 |
β |
| π high |
CVE-2022-25883 |
semver |
>= 6.0.0, < 6.3.1 |
6.3.1 |
β |
| π‘ medium |
CVE-2021-32050 |
mongodb |
>= 3.6.0, < 3.6.10 |
3.6.10 |
β |
| π΄ critical |
CVE-2023-45133 |
@babel/traverse |
< 7.23.2 |
7.23.2 |
β |
| π‘ medium |
CVE-2023-26159 |
follow-redirects |
< 1.15.4 |
1.15.4 |
β |
| π‘ medium |
CVE-2023-45857 |
axios |
>= 0.8.1, < 0.28.0 |
0.28.0 |
β |
| π΅ low |
CVE-2024-27088 |
es5-ext |
>= 0.10.0, < 0.10.63 |
0.10.63 |
β |
| π‘ medium |
CVE-2024-28849 |
follow-redirects |
<= 1.15.5 |
1.15.6 |
β |
| π‘ medium |
CVE-2024-29041 |
express |
< 4.19.2 |
4.19.2 |
β |
| π high |
CVE-2024-4068 |
braces |
< 3.0.3 |
3.0.3 |
β |
| π‘ medium |
CVE-2023-32695 |
socket.io-parser |
< 3.3.4 |
3.3.4 |
β |
| π‘ medium |
CVE-2024-4067 |
micromatch |
< 4.0.8 |
4.0.8 |
β |
| π high |
CVE-2024-45296 |
path-to-regexp |
< 0.1.10 |
0.1.10 |
β |
| π high |
CVE-2024-45590 |
body-parser |
< 1.20.3 |
1.20.3 |
β |
| π΅ low |
CVE-2024-43796 |
express |
< 4.20.0 |
4.20.0 |
β |
| π΅ low |
CVE-2024-43800 |
serve-static |
< 1.16.0 |
1.16.0 |
β |
| π΅ low |
CVE-2024-43799 |
send |
< 0.19.0 |
0.19.0 |
β |
| π΅ low |
CVE-2024-47764 |
cookie |
< 0.7.0 |
0.7.0 |
β |
| π high |
CVE-2024-52798 |
path-to-regexp |
< 0.1.12 |
0.1.12 |
β |
| π΄ critical |
CVE-2025-7783 |
form-data |
< 2.5.4 |
2.5.4 |
β |
| π΅ low |
CVE-2025-54798 |
tmp |
<= 0.2.3 |
0.2.4 |
β |
| π‘ medium |
CVE-2020-28500 |
lodash |
>= 4.0.0, < 4.17.21 |
4.17.21 |
PR |
| π‘ medium |
CVE-2025-56200 |
validator |
< 13.15.20 |
13.15.20 |
β |
| π‘ medium |
CVE-2025-64718 |
js-yaml |
< 3.14.2 |
3.14.2 |
β |
| π high |
CVE-2025-12758 |
validator |
< 13.15.22 |
13.15.22 |
β |
| π high |
CVE-2025-65945 |
jws |
< 3.2.3 |
3.2.3 |
β |
| π‘ medium |
CVE-2025-15284 |
qs |
< 6.14.1 |
6.14.1 |
β |
| π‘ medium |
CVE-2025-13465 |
lodash |
>= 4.0.0, <= 4.17.22 |
4.17.23 |
β |
| π‘ medium |
CVE-2025-61140 |
jsonpath |
< 1.2.0 |
1.2.0 |
β |
| π΅ low |
CVE-2026-2391 |
qs |
>= 6.7.0, <= 6.14.1 |
6.14.2 |
β |
| π high |
CVE-2026-1615 |
jsonpath |
<= 1.2.1 |
1.3.0 |
β |
| π high |
CVE-2026-25639 |
axios |
<= 0.30.2 |
0.30.3 |
β |
| π high |
CVE-2026-26996 |
minimatch |
< 3.1.3 |
3.1.3 |
β |
| π high |
GHSA-5c6j-r48x-rmvq |
serialize-javascript |
<= 7.0.2 |
7.0.3 |
β |
| π high |
CVE-2026-27903 |
minimatch |
< 3.1.3 |
3.1.3 |
β |
| π high |
CVE-2026-27904 |
minimatch |
< 3.1.4 |
3.1.4 |
β |
| π high |
CVE-2026-33228 |
flatted |
<= 3.4.1 |
3.4.2 |
β |
| π high |
CVE-2026-4867 |
path-to-regexp |
< 0.1.13 |
0.1.13 |
β |
| π high |
CVE-2026-33671 |
picomatch |
< 2.3.2 |
2.3.2 |
β |
| π‘ medium |
CVE-2026-33672 |
picomatch |
< 2.3.2 |
2.3.2 |
β |
| π high |
CVE-2026-4800 |
lodash |
>= 4.0.0, <= 4.17.23 |
4.18.0 |
β |
| π‘ medium |
CVE-2026-2950 |
lodash |
<= 4.17.23 |
4.18.0 |
β |
| π‘ medium |
GHSA-r4q5-vmmm-2653 |
follow-redirects |
<= 1.15.11 |
1.16.0 |
β |
| π‘ medium |
CVE-2026-40175 |
axios |
< 0.31.0 |
0.31.0 |
β |
| π‘ medium |
CVE-2025-62718 |
axios |
< 0.31.0 |
0.31.0 |
β |
| π high |
CVE-2026-42043 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π΅ low |
CVE-2026-42040 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42042 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42034 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42038 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42039 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-42041 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π high |
CVE-2026-42035 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-41907 |
uuid |
< 11.1.1 |
11.1.1 |
β |
| π high |
CVE-2026-44705 |
tmp |
< 0.2.6 |
0.2.6 |
β |
| π‘ medium |
CVE-2026-42036 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π high |
CVE-2026-42033 |
axios |
<= 0.31.0 |
0.31.1 |
β |
| π‘ medium |
CVE-2026-44490 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44496 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44486 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44487 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π high |
CVE-2026-44492 |
axios |
<= 0.31.1 |
0.32.0 |
β |
| π‘ medium |
CVE-2026-48038 |
joi |
< 17.13.4 |
17.13.4 |
β |
| π high |
CVE-2026-12143 |
form-data |
< 2.5.6 |
2.5.6 |
β |
| π΅ low |
CVE-2026-49356 |
@babel/core |
<= 7.29.0 |
7.29.6 |
β |
| π‘ medium |
CVE-2026-53550 |
js-yaml |
< 3.15.0 |
3.15.0 |
β |
| π high |
CVE-2026-13149 |
brace-expansion |
< 1.1.16 |
1.1.16 |
β |
| π‘ medium |
CVE-2026-67316 |
axios |
< 0.33.0 |
0.33.0 |
β |
| π‘ medium |
CVE-2026-67319 |
axios |
>= 0.8.0, < 0.33.0 |
0.33.0 |
β |
| π high |
CVE-2026-59869 |
js-yaml |
>= 3.0.0, < 3.15.0 |
3.15.0 |
β |
| π΅ low |
CVE-2026-12590 |
body-parser |
< 1.20.6 |
1.20.6 |
β |
| π high |
CVE-2026-69185 |
socket.io-parser |
< 3.3.6 |
3.3.6 |
β |
| π high |
CVE-2026-14257 |
brace-expansion |
< 1.1.17 |
1.1.17 |
β |
| π high |
CVE-2026-69152 |
brace-expansion |
< 1.1.18 |
1.1.18 |
β |
| π high |
GHSA-5p4m-2wfm-xmqj |
js-yaml |
>= 3.0.0, < 3.15.1 |
3.15.1 |
β |
| π‘ medium |
CVE-2026-85063 |
csv-parse |
< 7.0.2 |
7.0.2 |
β |
| π΅ low |
CVE-2026-84368 |
joi |
>= 17.2.0, < 17.13.6 |
17.13.6 |
β |
| π΅ low |
CVE-2026-84367 |
joi |
>= 16.0.0, < 17.13.5 |
17.13.5 |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π Security Alerts β IBM/libras
Attention: (no direct admin collaborators assigned to this repo β please add an admin to receive security notifications)
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.