Vulnerability Reportmongo-express:0.49

mongo-express:0.49
DIGESTsha256:5f53f6900c495c27264a34834abb96d0f9ae1340d888e2a2d8f8d4b59d24321b

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could execute arbitrary code in the mongo-express web interface, gain unauthorized access to MongoDB data, or perform denial of service attacks against the container. CVE-2019-10758 has an EPSS of 0.85, indicating active exploitation in the wild. No full mitigation is identified for the highest-severity vulnerabilities.

Vulnerabilities

Vulnerability Log

153 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2019-10758CRITICAL10
mongo-express
0.49.0
fixed in 0.54.0
84.8%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2020-7699CRITICAL9.8
express-fileupload
0.4.0
fixed in 1.1.9
4.7%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2021-3712CRITICAL9.62
libssl1.1
1.1.1d-r2
fixed in 1.1.1l-r0
50.4%
Actively Exploited
Directly Exposed
CVE-2022-38900HIGH8.62
decode-uri-component
0.2.0
fixed in 0.2.1
24.9%
High Exploitation Risk
Directly Exposed
CVE-2022-24999HIGH8.62
qs
6.5.1
fixed in 6.10.3, 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, 6.2.4
14.7%
High Exploitation Risk
Directly Exposed
CVE-2022-24999HIGH8.62
qs
6.5.2
fixed in 6.10.3, 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, 6.2.4
14.7%
High Exploitation Risk
Directly Exposed
CVE-2022-24999HIGH8.62
qs
6.7.0
fixed in 6.10.3, 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, 6.2.4
14.7%
High Exploitation Risk
Directly Exposed
CVE-2021-3450HIGH8.51
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Directly Exposed
CVE-2021-3450HIGH8.51
libssl1.1
1.1.1d-r2
fixed in 1.1.1k-r0
18.3%
High Exploitation Risk
Directly Exposed
CVE-2021-23337HIGH8.28
lodash
4.17.15
fixed in 4.17.21
22.4%
High Exploitation Risk
Directly Exposed
CVE-2020-7774HIGH8
y18n
3.2.1
fixed in 3.2.2, 4.0.1, 5.0.5
69.1%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2020-7774HIGH8
y18n
4.0.0
fixed in 3.2.2, 4.0.1, 5.0.5
69.1%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2020-7610HIGH7.84
bson
1.0.9
fixed in 1.1.4
2.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2020-36632HIGH7.84
flat
2.0.1
fixed in 1.6.2, 2.0.2, 3.0.1, 4.0.2, 5.0.1
1.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-29415HIGH7.84
ip
1.1.5
No fix yet
8.3%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2023-42282HIGH7.84
ip
1.1.5
fixed in 2.0.1, 1.1.9
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2021-3918HIGH7.84
json-schema
0.2.3
fixed in 0.4.0
3.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-4800HIGH7.84
lodash
4.17.15
fixed in 4.18.0
1.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2023-26136HIGH7.84
tough-cookie
2.4.3
fixed in 4.1.3
2.1%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2020-1967HIGH7.8
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1g-r0
53.3%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2021-23840HIGH7.8
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2020-1967HIGH7.8
libssl1.1
1.1.1d-r2
fixed in 1.1.1g-r0
53.3%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2021-23840HIGH7.8
libssl1.1
1.1.1d-r2
fixed in 1.1.1j-r0
50.7%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2021-3712HIGH7.7
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1l-r0
50.4%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2021-3449HIGH7.67
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1k-r0
63.5%
Actively Exploited
Directly Exposed
CVE-2021-3449HIGH7.67
libssl1.1
1.1.1d-r2
fixed in 1.1.1k-r0
63.5%
Actively Exploited
Directly Exposed
CVE-2019-15847HIGH7.5
libgcc
9.2.0-r3
fixed in 9.3.0-r0
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2019-15847HIGH7.5
libstdc++
9.2.0-r3
fixed in 9.3.0-r0
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-3807HIGH7.5
ansi-regex
3.0.0
fixed in 6.0.1, 5.0.1, 4.1.1, 3.0.1
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2022-24434HIGH7.5
dicer
0.2.5
No fix yet
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2022-27261HIGH7.5
express-fileupload
0.4.0
No fix yet
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2022-25881HIGH7.5
http-cache-semantics
3.8.1
fixed in 4.1.1
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2022-3517HIGH7.5
minimatch
3.0.4
fixed in 3.0.5
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2021-23343HIGH7.5
path-parse
1.0.6
fixed in 1.0.7
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2022-25883HIGH7.5
semver
5.3.0
fixed in 7.5.2, 6.3.1, 5.7.2
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2022-25883HIGH7.5
semver
5.7.1
fixed in 7.5.2, 6.3.1, 5.7.2
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2021-27290HIGH7.5
ssri
6.0.1
fixed in 6.0.2, 7.1.1, 8.0.1
4.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-25345HIGH7.5
swig-templates
2.0.2
No fix yet
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-8203HIGH7.4
lodash
4.17.15
fixed in 4.17.19
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-8203HIGH7.4
lodash.set
4.3.2
No fix yet
5.2%
Low-Moderate Risk
Directly Exposed
CVE-2020-8116HIGH7.3
dot-prop
3.0.0
fixed in 4.2.1, 5.1.1
3.1%
Low-Moderate Risk
Directly Exposed
CVE-2020-8116HIGH7.3
dot-prop
4.2.0
fixed in 4.2.1, 5.1.1
3.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-69873MEDIUM6.38
ajv
5.5.2
fixed in 8.18.0, 6.14.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-45590MEDIUM6.38
body-parser
1.18.2
fixed in 1.20.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45590MEDIUM6.38
body-parser
1.19.0
fixed in 1.20.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33750MEDIUM6.38
brace-expansion
1.1.11
fixed in 5.0.5, 3.0.2, 2.0.3, 1.1.13
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26996MEDIUM6.38
minimatch
3.0.4
fixed in 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2021-23372MEDIUM6.38
mongo-express
0.49.0
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-15284MEDIUM6.38
qs
6.5.1
fixed in 6.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15284MEDIUM6.38
qs
6.5.2
fixed in 6.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15284MEDIUM6.38
qs
6.7.0
fixed in 6.14.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2391MEDIUM6.38
qs
6.7.0
fixed in 6.14.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
2.0.3
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41907MEDIUM6.38
uuid
3.3.3
fixed in 11.1.1, 12.0.1, 13.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-21422MEDIUM6.1
mongo-express
0.49.0
fixed in 1.0.0-alpha.4
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2019-1551MEDIUM6.09
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1d-r3
14.3%
High Exploitation Risk
Directly Exposed
CVE-2019-1551MEDIUM6.09
libssl1.1
1.1.1d-r2
fixed in 1.1.1d-r3
14.3%
High Exploitation Risk
Directly Exposed
CVE-2020-1971MEDIUM5.9
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23841MEDIUM5.9
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-1971MEDIUM5.9
libssl1.1
1.1.1d-r2
fixed in 1.1.1i-r0
7.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23841MEDIUM5.9
libssl1.1
1.1.1d-r2
fixed in 1.1.1j-r0
7.5%
Low-Moderate Risk
Directly Exposed
CVE-2020-15366MEDIUM5.6
ajv
5.5.2
fixed in 6.12.3
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-7598MEDIUM5.6
minimist
0.0.10
fixed in 0.2.1, 1.2.3
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2020-7598MEDIUM5.6
minimist
0.0.8
fixed in 0.2.1, 1.2.3
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2020-7598MEDIUM5.6
minimist
1.2.0
fixed in 0.2.1, 1.2.3
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-27904MEDIUM5.52
minimatch
3.0.4
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-7783MEDIUM5.4
form-data
2.3.2
fixed in 2.5.4, 3.0.4, 4.0.4
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2017-16137MEDIUM5.3
debug
3.2.6
fixed in 2.6.9, 3.1.0, 3.2.7, 4.3.1
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2022-33987MEDIUM5.3
got
5.7.1
fixed in 12.1.0, 11.8.5
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2022-33987MEDIUM5.3
got
6.7.1
fixed in 12.1.0, 11.8.5
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2021-23362MEDIUM5.3
hosted-git-info
2.8.5
fixed in 2.8.9, 3.0.8
3.6%
Low-Moderate Risk
Directly Exposed
CVE-2020-28500MEDIUM5.3
lodash
4.17.15
fixed in 4.17.21
7.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-29041MEDIUM5.18
express
4.16.3
fixed in 4.19.2, 5.0.0-beta.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-28155MEDIUM5.18
request
2.88.0
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27903MEDIUM5.02
minimatch
3.0.4
fixed in 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2020-28928MEDIUM4.67
musl
1.1.24-r0
fixed in 1.1.24-r3
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-27088MEDIUM4.67
es5-ext
0.10.53
fixed in 0.10.63
0.5%
Theoretical Threat
Directly Exposed
CVE-2019-2391MEDIUM4.59
bson
1.0.9
fixed in 1.1.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-3711MEDIUM4.58
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1l-r0
87.8%
Actively Exploited
Post-Exploit
CVE-2021-3711MEDIUM4.58
libssl1.1
1.1.1d-r2
fixed in 1.1.1l-r0
87.8%
Actively Exploited
Post-Exploit
CVE-2021-30139MEDIUM4.5
apk-tools
2.10.4-r3
fixed in 2.10.6-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2024-47178MEDIUM4.5
basic-auth-connect
1.0.0
fixed in 1.1.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-13465MEDIUM4.5
lodash
4.17.15
fixed in 4.17.23
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2950MEDIUM4.5
lodash
4.17.15
fixed in 4.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-45296MEDIUM4.5
path-to-regexp
0.1.7
fixed in 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2024-52798MEDIUM4.5
path-to-regexp
0.1.7
fixed in 0.1.12
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-4867MEDIUM4.5
path-to-regexp
0.1.7
fixed in 0.1.13
0.5%
Theoretical Threat
Directly Exposed
CVE-2020-7608MEDIUM4.5
yargs-parser
9.0.2
fixed in 13.1.2, 15.0.1, 18.1.1, 5.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2021-42378MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42379MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42380MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2021-42381MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42382MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42383MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.1%
Low-Moderate Risk
Post-Exploit
CVE-2021-42384MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42385MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42386MEDIUM4.32
busybox
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42378MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42379MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42380MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2021-42381MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42382MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42383MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.1%
Low-Moderate Risk
Post-Exploit
CVE-2021-42384MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-42385MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-42386MEDIUM4.32
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-24842MEDIUM4.18
tar
4.4.13
fixed in 7.5.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2022-37434MEDIUM4.06
zlib
1.2.11-r3
fixed in 1.2.11-r4
15.9%
High Exploitation Risk
Post-Exploit
CVE-2024-43796MEDIUM4
express
4.16.3
fixed in 4.20.0, 5.0.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-43799MEDIUM4
send
0.16.2
fixed in 0.19.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-43800MEDIUM4
serve-static
1.13.2
fixed in 1.16.0, 2.1.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-4435LOW3.98
yarn
1.21.1
fixed in 1.22.13
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-21538LOW3.74
cross-spawn
5.1.0
fixed in 7.0.5, 6.0.6
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-23839LOW3.7
libcrypto1.1
1.1.1d-r2
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2021-23839LOW3.7
libssl1.1
1.1.1d-r2
fixed in 1.1.1j-r0
3.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-26960LOW3.62
tar
4.4.13
fixed in 7.5.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2020-7788LOW3.53
ini
1.3.5
fixed in 1.3.6
3.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-44906LOW3.53
minimist
0.0.10
fixed in 1.2.6, 0.2.4
4.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-44906LOW3.53
minimist
0.0.8
fixed in 1.2.6, 0.2.4
4.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-44906LOW3.53
minimist
1.2.0
fixed in 1.2.6, 0.2.4
4.6%
Low-Moderate Risk
Post-Exploit
CVE-2021-32804LOW3.35
tar
4.4.13
fixed in 3.2.2, 4.4.14, 5.0.6, 6.1.1
15.0%
High Exploitation Risk
Post-Exploit
CVE-2024-28863LOW3.31
tar
4.4.13
fixed in 6.2.1
0.9%
Theoretical Threat
Post-Exploit
CVE-2021-36159LOW3.28
apk-tools
2.10.4-r3
fixed in 2.10.7-r0
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2026-29786LOW3.21
tar
4.4.13
fixed in 7.5.10
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-47764LOW3.15
cookie
0.3.1
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-47764LOW3.15
cookie
0.4.0
fixed in 0.7.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-23745LOW3.11
tar
4.4.13
fixed in 7.5.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-37701LOW3.1
tar
4.4.13
fixed in 4.4.16, 5.0.8, 6.1.7
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2021-37712LOW3.1
tar
4.4.13
fixed in 4.4.18, 5.0.10, 6.1.9
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2021-37713LOW3.1
tar
4.4.13
fixed in 4.4.18, 5.0.10, 6.1.9
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-23950LOW3.01
tar
4.4.13
fixed in 7.5.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2021-32803LOW2.92
tar
4.4.13
fixed in 3.2.3, 4.4.15, 5.0.7, 6.1.2
7.8%
Low-Moderate Risk
Post-Exploit
CVE-2025-7339LOW2.89
on-headers
1.0.2
fixed in 1.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2019-10773LOW2.81
yarn
1.21.1
fixed in 1.22.0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2020-28928LOW2.8
musl-utils
1.1.24-r0
fixed in 1.1.24-r3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-31802LOW2.8
tar
4.4.13
fixed in 7.5.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-28831LOW2.7
busybox
1.31.1-r8
fixed in 1.31.1-r10
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2021-28831LOW2.7
ssl_client
1.31.1-r8
fixed in 1.31.1-r10
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2020-8131LOW2.7
yarn
1.21.1
fixed in 1.22.0
5.0%
Low-Moderate Risk
Post-Exploit
CVE-2021-42374LOW2.7
busybox
1.31.1-r8
fixed in 1.31.1-r11
0.6%
Theoretical Threat
Post-Exploit
CVE-2021-42374LOW2.7
ssl_client
1.31.1-r8
fixed in 1.31.1-r11
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-5889LOW2.63
brace-expansion
1.1.11
fixed in 2.0.2, 1.1.12, 3.0.1, 4.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2020-15095LOW2.24
npm
6.13.4
fixed in 6.14.6
0.4%
Theoretical Threat
Post-Exploit
CVE-2020-7754NONE0
npm-user-validate
1.0.0
fixed in 1.0.1
3.4%
Low-Moderate Risk
Not Applicable
GHSA-q3w9-g74q-vp5fNONE0
express-fileupload
0.4.0
fixed in 1.1.6-alpha.6
Not Applicable
CVE-2026-12143NONE0
form-data
2.3.2
fixed in 2.5.6, 3.0.5, 4.0.6
0.3%
Theoretical Threat
Not Applicable
NSWG-ECO-516NONE0
lodash
4.17.15
fixed in >=4.17.19
Not Applicable
GHSA-4xcv-9jjx-gfj3NONE0
mem
1.1.0
fixed in 4.0.0
Not Applicable
CVE-2023-52555NONE0
mongo-express
0.49.0
No fix yet
0.2%
Theoretical Threat
Not Applicable
GHSA-mh5c-679w-hh4rNONE0
mongodb
2.2.24
fixed in 3.1.13
Not Applicable
GHSA-jmqm-f2gx-4fjvNONE0
npm-registry-fetch
4.0.2
fixed in 4.0.5, 8.1.1
Not Applicable
GHSA-xgh6-85xh-479pNONE0
npm-user-validate
1.0.0
fixed in 1.0.1
Not Applicable
CVE-2026-53655NONE0
tar
4.4.13
fixed in 7.5.16
0.1%
Theoretical Threat
Not Applicable