HIGH 7.5 npm

body-parser vulnerable to denial of service when url encoding is enabled

GHSA-qwcr-r2fm-qrc7 · CVE-2024-45590

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

Patches

this issue is patched in 1.20.3

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes