Skip to content

Conversation

@Xilis
Copy link

@Xilis Xilis commented Jan 5, 2026

Summary

Bumps Express from 4.21.2 to 4.22.1 to address CVE-2025-15284 (qs arrayLimit bypass allowing DoS via memory exhaustion).

Changes

  • package.json: express 4.21.2 → 4.22.1
  • packages/platform-express/package.json: express 4.21.2 → 4.22.1
  • package-lock.json: updated (qs now at 6.14.1)

@Xilis Xilis force-pushed the fix/express-version-flexibility branch from e4d88c1 to 2f853c0 Compare January 5, 2026 09:42
@Xilis Xilis force-pushed the fix/express-version-flexibility branch from 2f853c0 to eb0f29d Compare January 5, 2026 09:45
@kamilmysliwiec kamilmysliwiec merged commit 5ab165a into nestjs:10.4.20 Jan 8, 2026
1 of 2 checks passed
@mmollick
Copy link

mmollick commented Jan 8, 2026

body-parser also relies on [email protected] so this PR doesn't fully address the CVE

@Xilis
Copy link
Author

Xilis commented Jan 9, 2026

Thanks @mmollick for catching this! Opened #16178 to address it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants