HTTP response serializer middleware for the middy framework
84%
Total Score
healthy
Healthy release with frequent updates, trusted provenance, and an active organization-backed project.
All 81 recent commits came from one contributor, creating a meaningful concentration risk; organization backing partly offsets handoff risk but does not provide evidence of a second currently active contributor.
The repository name does not match the package and its README does not mention this package, which creates some uncertainty about package-to-repository alignment; the monorepo context makes a name mismatch ordinary but does not remove the README gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-293375 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @middy/http-response-serializer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 1.0.0 - 7.6.7. | 1.0.0 - 7.6.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@middy/util Version 7.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.