Skip to content

chore(deps): update dependency nexmo to v2

180cf87
Select commit
Loading
Failed to load commit list.
Open

chore(deps): update dependency nexmo to v2 (main) #26

chore(deps): update dependency nexmo to v2
180cf87
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Mar 28, 2026 in 1m 9s

Security Report

You have successfully remediated 14 vulnerabilities, but introduced 6 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-7783

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/form-data/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> request-2.88.2.tgz

     -> ❌ form-data-2.3.3.tgz (Vulnerable Library)

High 8.7 Not Defined 0.1% Transitive form-data-2.3.3.tgz nexmo-2.9.1.tgz Transitive 2.5.4 None

Reachable

CVE-2023-26136

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/tough-cookie/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> request-2.88.2.tgz

     -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library)

Medium 6.5 Proof of concept 6.4% Transitive tough-cookie-2.5.0.tgz nexmo-2.9.1.tgz Transitive 4.1.3 None

Reachable

CVE-2022-23540

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/jsonwebtoken/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 6.4 Not Defined 0.0% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.9.1.tgz Transitive 9.0.0 None

Reachable

CVE-2023-28155

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/request/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> ❌ request-2.88.2.tgz (Vulnerable Library)

Medium 6.1 Not Defined 0.6% Transitive request-2.88.2.tgz nexmo-2.9.1.tgz Transitive @cypress/request - 3.0.0 None

Reachable

CVE-2022-23539

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/jsonwebtoken/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 5.9 Not Defined 0.1% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.9.1.tgz Transitive 9.0.0 None

Reachable

CVE-2022-23541

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/jsonwebtoken/package.json

Dependency Hierarchy:

-> nexmo-2.9.1.tgz (Root Library)

   -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library)

Medium 5.0 Not Defined 0.1% Transitive jsonwebtoken-8.5.1.tgz nexmo-2.9.1.tgz Transitive 9.0.0 None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2024-43796 express-4.18.2.tgz
CVE-2024-29041 express-4.18.2.tgz
CVE-2020-36604 hoek-2.16.3.tgz
CVE-2025-65945 jws-3.2.2.tgz
CVE-2022-23539 jsonwebtoken-7.4.3.tgz
CVE-2026-2391 qs-6.11.0.tgz
CVE-2022-23541 jsonwebtoken-7.4.3.tgz
CVE-2024-47764 cookie-0.5.0.tgz
CVE-2024-52798 path-to-regexp-0.1.7.tgz
CVE-2025-15284 qs-6.11.0.tgz
CVE-2022-23540 jsonwebtoken-7.4.3.tgz
CVE-2024-45590 body-parser-1.20.1.tgz
CVE-2024-45296 path-to-regexp-0.1.7.tgz
CVE-2026-4867 path-to-regexp-0.1.7.tgz

Base branch total remaining vulnerabilities: 14
Base branch commit: null


Total libraries scanned: 127

Scan token: 9eeb7c05b49643d9bfddfa416fe4273f