HIGH 7.5 npm

body-parser vulnerable to denial of service when url encoding is enabled

GHSA-qwcr-r2fm-qrc7 · CVE-2024-45590

Published · Modified

Description

Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

Patches

this issue is patched in 1.20.3

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes