Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
5 active CVEs reported via OSV.dev
Express ressource injection
No Charset in Content-Type Header in express
Express Open Redirect vulnerability
express vulnerable to XSS via response.redirect()
Express.js Open Redirect in malformed URLs
Other Web Framework projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Express โ without relying on volunteer maintainers.
Talk to an Expert โ