Known vulnerabilities in Express.js Express 4.19.0

Vendor: Express.js
Website: https://expressjs.com/
Total Security Bulletins: 3

Security bulletins (3)

Secuity bulletin Severity Status Published
SB2025120158: Prototype pollution in Express.js Medium
Patched
01.12.2025
SB2024091250: XSS in Express.js framework Medium
Patched
12.09.2024
SB2024041530: Open redirect in Express Medium
Patched
15.04.2024