Skip to content

Update dependency nexmo to v2.4.1

a914168
Select commit
Loading
Failed to load commit list.
Open

Update dependency nexmo to v2.4.1 (main) #12

Update dependency nexmo to v2.4.1
a914168
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Dec 4, 2025 in 2m 15s

Security Report

You have successfully remediated 7 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2024-43800

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> express-4.16.4.tgz (Root Library)

   -> ❌ serve-static-1.13.2.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.2% Transitive serve-static-1.13.2.tgz express-4.16.4.tgz Transitive 1.16.0 #6

Reachable

CVE-2023-26136

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nexmo-2.4.1.tgz (Root Library)

   -> request-2.88.2.tgz

     -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library)

Medium 6.5 Proof of concept 6.8999996% Transitive tough-cookie-2.5.0.tgz nexmo-2.4.1.tgz Transitive 4.1.3 None

Unreachable

CVE-2022-23540

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nexmo-2.4.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 6.4 Not Defined 0.0% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.4.1.tgz Transitive 9.0.0 None

Unreachable

CVE-2023-28155

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nexmo-2.4.1.tgz (Root Library)

   -> ❌ request-2.88.2.tgz (Vulnerable Library)

Medium 6.1 Not Defined 0.5% Transitive request-2.88.2.tgz nexmo-2.4.1.tgz Transitive @cypress/request - 3.0.0 None

Unreachable

CVE-2022-23539

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nexmo-2.4.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 5.9 Not Defined 0.1% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.4.1.tgz Transitive 9.0.0 None

Unreachable

CVE-2022-23541

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

-> nexmo-2.4.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.4.1.tgz Transitive 9.0.0 None

Unreachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-15366 ajv-6.5.5.tgz
CVE-2022-23541 jsonwebtoken-8.3.0.tgz
CVE-2022-23539 jsonwebtoken-8.3.0.tgz
CVE-2021-3918 json-schema-0.2.3.tgz
CVE-2023-26136 tough-cookie-2.4.3.tgz
CVE-2022-23540 jsonwebtoken-8.3.0.tgz
CVE-2023-28155 request-2.88.0.tgz

Base branch total remaining vulnerabilities: 16
Base branch commit: null


Total libraries scanned: 107

Scan token: ed63f466f3b64b4a8443b45e76155504