{"note":"Free cached sample. The paid endpoint audits your manifest live.","summary":{"packages":3,"with_vulnerabilities":2,"deprecated":0,"behind_latest":2,"unpinned":1,"lookup_errors":0},"rows":[{"ecosystem":"npm","name":"lodash","requested":"4.17.20","pinned":"4.17.20","latest":"4.18.1","latest_published":"2026-04-01T21:01:20Z","behind":true,"license":"MIT","deprecated":false,"weekly_downloads":128527290,"vulnerabilities":[{"id":"GHSA-29mw-wpgm-hmr9","aliases":["CVE-2020-28500"],"summary":"Regular Expression Denial of Service (ReDoS) in lodash","severity":"MODERATE","fixed_in":"4.17.21"},{"id":"GHSA-35jh-r3h4-6jhm","aliases":["CVE-2021-23337","CVE-2026-4800"],"summary":"Command Injection in lodash","severity":"HIGH","fixed_in":"4.17.21"},{"id":"GHSA-f23m-r3pf-42rh","aliases":["CVE-2025-13465","CVE-2026-2950"],"summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","severity":"MODERATE","fixed_in":"4.18.0"},{"id":"GHSA-r5fr-rjxr-66jc","aliases":["CVE-2021-23337","CVE-2026-4800"],"summary":"lodash vulnerable to Code Injection via `_.template` imports key names","severity":"HIGH","fixed_in":"4.18.0"},{"id":"GHSA-xxjr-mmjv-4gpg","aliases":["CVE-2025-13465","CVE-2026-2950"],"summary":"Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions","severity":"MODERATE","fixed_in":"4.17.23"}],"vulnerability_count":5,"max_severity":"HIGH","notes":[]},{"ecosystem":"npm","name":"express","requested":null,"pinned":null,"latest":"5.2.1","latest_published":"2025-12-01T20:49:43Z","behind":null,"license":"MIT","deprecated":false,"weekly_downloads":101489586,"vulnerabilities":[],"vulnerability_count":0,"max_severity":null,"notes":["no version given; audited at latest"]},{"ecosystem":"pypi","name":"requests","requested":"2.25.0","pinned":"2.25.0","latest":"2.34.2","latest_published":"2026-05-14T19:25:26Z","behind":true,"license":"Apache-2.0","deprecated":false,"weekly_downloads":null,"vulnerabilities":[{"id":"GHSA-9hjg-9r4m-mvj7","aliases":["CVE-2024-47081"],"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","severity":"MODERATE","fixed_in":"2.32.4"},{"id":"GHSA-9wx4-h78v-vm56","aliases":["CVE-2024-35195"],"summary":"Requests `Session` object does not verify requests after making first request with verify=False","severity":"MODERATE","fixed_in":"2.32.0"},{"id":"GHSA-gc5v-m9x4-r6x2","aliases":["CVE-2026-25645"],"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","severity":"MODERATE","fixed_in":"2.33.0"},{"id":"GHSA-j8r2-6x86-q33q","aliases":["CVE-2023-32681"],"summary":"Unintended leak of Proxy-Authorization header in requests","severity":"MODERATE","fixed_in":"2.31.0"},{"id":"PYSEC-2023-74","aliases":["CVE-2023-32681"],"summary":"","severity":"UNKNOWN","fixed_in":"74ea7cf7a6a27a4eeb2ae24e162bcc942a6706d5"},{"id":"PYSEC-2026-1872","aliases":["CVE-2024-47081"],"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","severity":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","fixed_in":"2.32.4"},{"id":"PYSEC-2026-1873","aliases":["CVE-2024-35195"],"summary":"Requests `Session` object does not verify requests after making first request with verify=False","severity":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","fixed_in":"2.32.0"},{"id":"PYSEC-2026-2275","aliases":["CVE-2026-25645"],"summary":"","severity":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","fixed_in":"2.33.0"}],"vulnerability_count":8,"max_severity":"MODERATE","notes":[]}],"max_packages":50,"sources":["api.deps.dev","api.osv.dev","registry.npmjs.org","api.npmjs.org","pypi.org"],"elapsed_ms":1221,"generated_at":"2026-09-24T18:31:41.220Z"}